Inspur ClusterEngine V4.0 RCE

Published on 16 Jun 2021
Vulnerability

ClusterEngine is a cluster management programme created by Inspur on its own. Inspur ClusterEngine V4.0 has a Remote Code Execution flaw. A malicious hacker may send bogus login packets to the control server. It has been deemed critical. This flaw affects any unidentified processing of the Control Server portion. A privilege escalation vulnerability is created when an undefined input is manipulated.

Mitigation / Precaution

  • To unlock the defence, upgrade your Security Gateway product to the most recent IPS update.
  • Security Gateway R80 / R77 / R75
    • In the IPS column, press Protections, then use the Search tool to locate the Inspur ClusterEngine Remote Code Execution (CVE-2020-21224) security and Edit its parameters.
    • Policy must be installed on all Security Gateways.
Anandhu Krishnan
Written by
Lead Engineer

Anandhu is an accomplished Senior Lead Engineer with a strong focus on back-end development. His expertise lies in architecting and optimizing the core of software applications to ensure they run smoothly and efficiently. With a meticulous attention to detail and a deep understanding of data management and server-side operations, Anandhu has been a driving force behind the success of various back-end projects.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo