{"id":7428,"date":"2022-03-17T15:39:01","date_gmt":"2022-03-17T22:39:01","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=7428"},"modified":"2024-04-29T10:56:37","modified_gmt":"2024-04-29T17:56:37","slug":"after-a-year-dhs-cisa-adds-cve-2021-21315-to-kevs-catalog","status":"publish","type":"post","link":"https:\/\/webdev.securin.xyz\/articles\/after-a-year-dhs-cisa-adds-cve-2021-21315-to-kevs-catalog\/","title":{"rendered":"After a year, DHS CISA Adds CVE-2021-21315 to KEVs Catalog!"},"content":{"rendered":"\t\t
In 2021, a remote code execution vulnerability was discovered in the System Information Library for Node.JS<\/a>, an open-source collection of functions that aid in retrieving detailed information about CPU, hardware, battery, network, services, and system processes.<\/p> More than 56,000 open instances of NodeJs packages are exposed to the remote code injection bug, with 38% of them in the United States and 9% in China. Further, cyber research intelligence reports that this CVE 2021-21315 is hotly discussed on dark forums among hackers, posing a high threat to numerous organizations.<\/p> This vulnerability is tracked as CVE 2021-21315<\/a> and earned a CVSS v3 score of 7.8 (high). In this case, the RCE bug falls under a vulnerability category described as CWE-78 that leads to Improper Neutralization of Special Elements used in an OS Command, ranking fifth<\/a> in the Top 25 Software Weaknesses.<\/p> Interestingly enough, over a year of CVE disclosure, CISA added this CVE to its catalog of Known Exploited Vulnerabilities (KEV), urging organizations to patch it immediately.<\/p>