peter bassill · operator
$ cve CVE-2021-21315 JSON

CVE-2021-21315 KEV

7.1
HIGH · CVSS 3.1 · EPSS 90.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-02-01.

Description

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

Scoring

CVSS7.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS90.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-02-01
Public exploitnone known
Published2021-02-16
Last modified2026-06-17

CISA KEV

NameSystem Information Library for Node.JS Command Injection
Added2022-01-18
Due2022-02-01
Vendor / productNpm package / System Information Library for Node.JS
Ransomware usenone reported

Affected (2)

VendorProduct
apachecordova
systeminformationsysteminformation

References

→ the Explorer  ·  watch your stack  ·  NVD