.. / CVE-2020-21224

Exploit for Inspur ClusterEngine 4.0 - Remote Code Execution (CVE-2020-21224)

Description:

Inspur ClusterEngine V4.0 is suscptible to a remote code execution vulnerability. A remote attacker can send a malicious login packet to the control server.

Nuclei Template

View the template here CVE-2020-21224.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-21224.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://github.com/NS-Sp4ce/Inspur/
https://github.com/NS-Sp4ce/Inspur/tree/master/ClusterEngineV4.0%20Vul
https://nvd.nist.gov/vuln/detail/CVE-2020-21224
https://github.com/SexyBeast233/SecBooks