Vulnerabilities > CVE-2021-32935 - Deserialization of Untrusted Data vulnerability in Cognex In-Sight OPC Server

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
cognex
CWE-502
critical

Summary

The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

Common Weakness Enumeration (CWE)