CVE-2021-21315 Scanner

Targets service parameters passed to si.inetLatency(), si.inetChecksite(), si.services(), and si.processLoad() functions. Attacker achieves arbitrary command execution.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

15 seconds

Time Interval

1 month 5 days

Scan only one

URL

Toolbox

The System Information Library for Node.JS, also known as npm package "systeminformation," is an open source collection of functions that retrieve detailed hardware, system, and operating system information. This library is commonly used by developers and system administrators to gather crucial information about their systems in order to troubleshoot issues and optimize performance. With its user-friendly interface and ease of use, systeminformation has become a popular tool within the Node.JS community.

CVE-2021-21315 is a command injection vulnerability that arises due to improper input validation in the systeminformation library. The vulnerability occurs when user-supplied data is passed to functions that execute system commands without adequate sanitization. Specifically, the library fails to properly filter or escape special characters in service parameters, allowing an attacker to inject arbitrary OS commands.

The vulnerable endpoints include functions such as si.inetLatency(), si.inetChecksite(), si.services(), and si.processLoad(). These functions accept parameters that are directly concatenated into shell commands. For example, the si.inetLatency() function takes a hostname parameter that is passed to the ping command without sanitization, enabling an attacker to inject additional commands using shell metacharacters like semicolons or backticks.

If exploited, this vulnerability allows an attacker to execute arbitrary commands on the server running the Node.JS application. This can lead to full system compromise, including data theft, installation of malware, or lateral movement within the network. Given the CVSS score of 7.8, the impact is severe, especially in production environments where the library is used for system monitoring or management.

Get started to protecting your digital assets