CVE-2021-32935 - CVE House
Back to Database
Status published High CVE-2021-32935

Cognex In-Sight OPC Server - Deserialization of Untrusted Data

Vulnerability Description

The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32935

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Amir Preminger of Claroty reported this vulnerability to CISA.

Affected Vendor

Affected Software

In-Sight OPC Server
Vulnerable Versions:
All

Timeline

Official Publish: May 23rd, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)