Vulnerabilities > CVE-2021-32935 - Deserialization of Untrusted Data vulnerability in Cognex In-Sight OPC Server

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
cognex
CWE-502
critical

Summary

The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

Vulnerable Configurations

Part Description Count
Application
Cognex
1

Common Weakness Enumeration (CWE)