
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47772 is a buffer overflow vulnerability in the text file import functionality of 10-Strike Network Inventory Explorer Pro version 9.31 that allows arbitrary code execution, including triggering reverse shells. The CVE was assigned by VulnCheck and published to NVD on January 15, 2026, despite the CVE identifier year suggesting earlier discovery. Only version 9.31 of the Pro edition is confirmed affected. It carries a CVSS v3.1 base score of 9.8 (Critical) assigned by VulnCheck, and a CVSS v4.0 base score of 8.4 (High) (NVD, Exploit-DB).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), rooted in insufficient bounds checking during the parsing of text files imported into the application. An attacker crafts a malicious text file with a carefully constructed oversized payload that overflows a buffer, enabling control of program execution flow — a technique consistent with SEH (Structured Exception Handler) overwrite exploitation on Windows. Exploitation requires a user to import the malicious file into the application, making it a local/social-engineering attack vector in practice, though the CNA assigned a network attack vector in CVSS v3.1. A public exploit is available on Exploit-DB (EDB-50472) (Exploit-DB, NVD).
Successful exploitation results in arbitrary code execution on the target system with the privileges of the user running the application, compromising confidentiality, integrity, and availability. An attacker can establish a reverse shell, exfiltrate sensitive network inventory data managed by the application, install persistent malware, or use the compromised host as a pivot point for lateral movement within the network. Given that Network Inventory Explorer is typically used by IT administrators, a compromise could expose sensitive infrastructure details (NVD, Exploit-DB).
A public proof-of-concept exploit is available on Exploit-DB (EDB-50472), referenced by both VulnCheck and CISA-ADP (Exploit-DB, NVD). There is no confirmed evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.0027 (0.27%), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
cmd.exe, powershell.exe) with no corresponding user-initiated action.No vendor patch has been publicly confirmed for version 9.31 at the time of publication. Organizations should immediately restrict access to the text file import functionality and avoid importing text files from untrusted or unverified sources. Network-level controls should be implemented to limit access to systems running this software, and users should be advised not to open files from unknown origins. Consider monitoring for or blocking outbound connections from the application process, and evaluate migration to an alternative inventory management solution until a patch is available (NVD, 10-Strike).
The vulnerability received brief coverage in automated CVE digest publications following its NVD publication in January 2026, including mention in CISA's weekly vulnerability bulletin for the week of January 12, 2026. No notable independent researcher commentary or significant social media discussion has been identified beyond automated CVE tracking feeds.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."