2N Access Commander
cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*
- 3.4.1
An OS command injection vulnerability has been identified in the user synchronization API endpoint of 2N Access Commander version 3.4.1. This issue arises from inadequate input validation, allowing for the injection of operating system commands. Exploitation of this vulnerability requires authentication with administrator privileges.
Exploitation of this vulnerability allows for OS command injection, where an authenticated administrator can execute arbitrary commands on the server's operating system.
Users can upgrade to 2N Access Commander version 3.5 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.