Security Advisory

CVE-2021-40396

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-01-28 19:09:28
Last updated 2025-04-15 19:22:27
Assigner talos
State PUBLISHED

Description

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.