S4E just found a high-severity finding from [ai] pa ssl inspection control
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVE

CVE-2021-21315

7.8
CVSShigh
Requires local system access · no authentication required.
Description

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

Attack Vector
Local
Privileges Req.
None
User Interaction
None
systeminformation
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE-2021-21315 Scanner

Targets service parameters passed to si.inetLatency(), si.inetChecksite(), si.services(), and si.processLoad() functions. Attacker achieves arbitrary command execution.

Used 2.7k times · 3.3k assets checked · url

CVE history: systeminformation

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →