CVE-2021-26726
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78, CWE-209, CWE-272, CWE-305, CWE-330
- Affected
- valmet/dna
- Source
- prodsec@nozominetworks.com
References
- https://www.nozominetworks.com/labs/vulnerability-advisories/cve-2021-26726/Third Party Advisory
- https://www.valmet.com/about-us/research-and-development/vulnerabilityadvisories/Vendor Advisory
- https://www.nozominetworks.com/labs/vulnerability-advisories/cve-2021-26726/Third Party Advisory
- https://www.valmet.com/about-us/research-and-development/vulnerabilityadvisories/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.