'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-05-06 | |
| Rule Name: | Inspur ClusterEngine Command Injection Vulnerability (CVE-2020-21224) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Inspur ClusterEngine is an application software developed by Inspur, a Chinese technology company. A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server. | |
| Impact: | Successful exploitation allows an attacker to execute arbitrary system commands on the target server, leading to complete system compromise, data theft, and further lateral movement in the network. | |
| Affected OS: | Linux | |
| Reference: | CVE-2020-21224 |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: https://www.inspur.com/lcjtww/psirt/security-advisories/2485095/index.html |