Security readout for executives and security teams
Plain-English summary
CVE-2021-37450 is a reflected cross-site scripting issue in NCH IVM Attendant 5.12 and earlier. A malicious link could cause script to run in a user’s browser if they visit it. Business impact depends on whether the IVM web interface is reachable and who can be tricked into opening crafted links.
Executive priority
Handle as a targeted remediation item, especially for exposed or administrator-facing deployments. It is not KEV-listed in the provided data, but reflected XSS with a public PoC can still create session and account-risk scenarios.
Technical view
The CVE describes reflected XSS through the /ogmprop?id= parameter in NCH IVM Attendant v5.12 and earlier. The bundle provides no CVSS score, CWE mapping, authentication context, or vendor fix details. A public proof-of-concept reference is cited, but offensive details should not be reused for validation.
Likely exposure
Exposure is most likely where NCH IVM Attendant v5.12 or earlier is installed and its web management interface is reachable by users or the internet. Systems isolated to trusted administrative networks have lower practical risk.
Exploitation context
The source bundle cites a public proof-of-concept reference, but does not show active exploitation. The CVE is not marked as CISA KEV in the provided data. Treat exploitability as plausible, not proven at scale.
Researcher notes
Evidence is sparse: the CVE description identifies the endpoint and affected version range, while the bundle lacks scoring, root-cause detail, patch status, and authentication requirements. Validation should focus on exposure, version confirmation, and safe reproduction boundaries.
Mitigation direction
- Inventory NCH IVM Attendant deployments and identify versions 5.12 or earlier.
- Check NCH guidance and apply any verified vendor update or replacement.
- Restrict the IVM web interface to trusted administrative networks.
- Disable or remove exposed instances that are no longer operationally required.
- Monitor requests involving /ogmprop and unusual id parameter values.
Validation and detection
- Confirm whether NCH IVM Attendant is present in asset inventories.
- Verify installed versions and flag 5.12 or earlier for review.
- Check whether the web interface is internet-accessible or broadly reachable internally.
- Review access logs for unusual /ogmprop?id= activity.
- Use approved, non-invasive testing to confirm reflected input is not executable script.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-37450 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.nch.com.au/ivm/index.htmlCVE reference · x_refsource_MISC
- https://github.com/0xfml/poc/blob/main/NCH/IVM_5.12_XSS.mdCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
