{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T23:23:05.472","vulnerabilities":[{"cve":{"id":"CVE-2021-32957","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2022-04-01T23:15:09.757","lastModified":"2024-11-21T06:08:00.263","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking."},{"lang":"es","value":"Una función en MDT AutoSave versiones anteriores a v6.02.06, es usado para recuperar información del sistema para un proceso específico, y esta recopilación de información ejecuta múltiples comandos y resume la información en un XML. Esta función y el proceso subsiguiente dan la ruta completa al ejecutable y, por lo tanto, son vulnerables al secuestro binario"}],"metrics":{"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:auvesy-mdt:autosave:*:*:*:*:*:*:*:*","versionEndExcluding":"6.02.06","matchCriteriaId":"8F0612E0-E5EE-45B1-B49C-BD1296B9EACB"},{"vulnerable":true,"criteria":"cpe:2.3:a:auvesy-mdt:autosave:*:*:*:*:*:*:*:*","versionStartIncluding":"7.00","versionEndIncluding":"7.04","matchCriteriaId":"8450FA45-0C07-42D5-B817-AC990579D4F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:*:*:*:*:*:*:*:*","versionEndExcluding":"4.01","matchCriteriaId":"DDA02918-09D4-43B6-95E6-3023E3DEE57A"},{"vulnerable":true,"criteria":"cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:5.00:*:*:*:*:*:*:*","matchCriteriaId":"682D5F51-4153-47C3-961C-6C5B4A124E3D"}]}]}],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-189-02","source":"ics-cert@hq.dhs.gov","tags":["Mitigation","Third Party Advisory","US Government Resource"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-189-02","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","US Government Resource"]}]}}]}