VYPR
High severity7.5NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026

CVE-2021-20707

CVE-2021-20707

Description

Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..

Affected products

7
  • NEC/Clusterpro X2 versions
    cpe:2.3:a:nec:clusterpro_x:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:nec:clusterpro_x:*:*:*:*:*:windows:*:*range: >=1.0,<=4.3
    • (no CPE)range: <=4.3
  • cpe:2.3:a:nec:clusterpro_x_singleserversafe:*:*:*:*:*:windows:*:*
    Range: >=1.0,<=4.3
  • cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:windows:*:*range: >=1.0,<=4.3
    • (no CPE)range: <=4.3
  • cpe:2.3:a:nec:expresscluster_x_singleserversafe:*:*:*:*:*:windows:*:*
    Range: >=1.0,<=4.3
  • Range: CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.