AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-3621

HIGH · CVSS 8.8 EPSS 2.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-12-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-3621
Severity
HIGH
CVSS
8.8
EPSS
2.52%

Original NVD Description

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.