SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22153

A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the…

HIGH 7.3EPSS 0.96%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
0.96% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-1236
Affected
blackberry/unified endpoint management
Source
secure@blackberry.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.