NEC CLUSTERPRO X and EXPRESSCLUSTER X OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in multiple versions of CLUSTERPRO X and EXPRESSCLUSTER X for Linux. This vulnerability allows an attacker to execute arbitrary operating system commands without authentication by sending specially crafted network packets to the application.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands, potentially allowing for further system compromise or disruption.

Remediation

Users are advised to update to EXPRESSCLUSTER X 4.3 for Linux (internal version 4.3.4-1) or EXPRESSCLUSTER X 5.3 for Linux (internal version 5.3.0-1) or later. For CLUSTERPRO X, the same update guidance applies. Additionally, a workaround is to enable the firewall and block unnecessary communication, allowing connection requests only from hosts belonging to the cluster for specific ports.

Added: Nov 7, 2025, 2:17 AM
Updated: Nov 7, 2025, 4:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
7.0
remediation
8.3
relevance
0.9
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.