NEC EXPRESSCLUSTER X
cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:*:*, +3 more
- 4.0
- 4.1
- 4.2
- 4.3
- 5.0
- 5.1
- 5.2
A command injection vulnerability has been identified in multiple versions of CLUSTERPRO X and EXPRESSCLUSTER X for Linux. This vulnerability allows an attacker to execute arbitrary operating system commands without authentication by sending specially crafted network packets to the application.
Exploitation of this vulnerability could lead to unauthorized execution of operating system commands, potentially allowing for further system compromise or disruption.
Users are advised to update to EXPRESSCLUSTER X 4.3 for Linux (internal version 4.3.4-1) or EXPRESSCLUSTER X 5.3 for Linux (internal version 5.3.0-1) or later. For CLUSTERPRO X, the same update guidance applies. Additionally, a workaround is to enable the firewall and block unnecessary communication, allowing connection requests only from hosts belonging to the cluster for specific ports.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.