LiveActive security incident?Get immediate response
CVE Record

CVE-2021-41316: The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.

The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Device42 fixed a flaw in Main Appliance versions before 17.05.01 where the Nmap Discovery utility failed to sanitize user input. A user who can add or edit those discovery jobs could cause arbitrary file overwrite as root on the Remote Collector, creating serious integrity and availability risk.

Executive priority

Treat this as a high-priority upgrade and access-control review for Device42 environments. The business risk is concentrated but serious: a permitted discovery-job user could affect root-owned files on collection infrastructure used for asset discovery.

Technical view

The issue is argument injection in Device42 Nmap Discovery job handling. The CVE states an attacker with add/edit job permissions can inject an extra argument and overwrite arbitrary files as root on the Remote Collector. The source bundle names Device42 Main Appliance before 17.05.01 as affected; CVSS and CWE data are not provided.

Likely exposure

Exposure is most likely in Device42 environments running Main Appliance before 17.05.01, using Nmap Discovery, and delegating job creation or editing permissions. Remote Collector deployments are especially relevant because the described file overwrite occurs there.

Exploitation context

The source bundle does not show KEV listing or active exploitation evidence. Exploitation is not described as unauthenticated; it requires permissions to add or edit Nmap Discovery jobs. No exploit code or public weaponization details are provided in the supplied sources.

Researcher notes

Core facts are clear, but public metadata is sparse: no CVSS, CWE, KEV status, or detailed vendor remediation procedure appears in the bundle. The key validation angle is whether vulnerable Device42 versions, Nmap Discovery, Remote Collectors, and delegated job-management permissions intersect.

Mitigation direction

  • Upgrade Device42 Main Appliance to 17.05.01 or later.
  • Review Device42 vendor guidance for any additional fixed-version notes.
  • Restrict Nmap Discovery job creation and editing permissions.
  • Audit Remote Collector exposure and administrative access paths.
  • Disable or limit Nmap Discovery where not operationally required.

Validation and detection

  • Inventory Device42 Main Appliance versions across the environment.
  • Confirm whether Nmap Discovery is enabled or used.
  • Identify Remote Collectors associated with vulnerable appliances.
  • Review users or roles allowed to add or edit discovery jobs.
  • Check change records for upgrade to version 17.05.01 or later.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-41316 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.