AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-33672

CRITICAL · CVSS 9.6 EPSS 1.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-14 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.6. See the original NVD description below for full technical details.

CVE
CVE-2021-33672
Severity
CRITICAL
CVSS
9.6
EPSS
1.10%

Original NVD Description

Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands in the chat recipient's scope. This could lead to a complete compromise of their confidentiality, integrity, and could temporarily impact their availability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)