CVE-2021-20527

CVSS v3 Score
6.0
Medium
CVSS v2 Score
6.5
Medium

Vulnerability Description

IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.

CVSS:6.0(Medium)

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

CWE-772024
CVSS:6.0(Medium)

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

CWE-772024
CVSS:5.9(Medium)

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials...

CWE-772020
CVSS:5.9(Medium)

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands int...

CWE-772020
CVSS:5.9(Medium)

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.

CWE-772020
CVSS:5.9(Medium)

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

CWE-772021