PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-3855 Liman Central Management System CVE debrief

A command injection vulnerability in Liman Central Management System (Port MYS) allows authenticated attackers to execute arbitrary commands. The flaw exists in HTTP/Controllers, CronMail, and Jobs modules. Affected versions span 1.7.0 through 1.8.3-462. The vulnerability was disclosed in March 2023 with a CVSS 3.1 score of 8.8 (High severity).

Vendor
Liman Central Management System
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2023-03-01
Original CVE updated
2026-05-18
Advisory published
2023-03-01
Advisory updated
2026-05-18

Who should care

Organizations running Liman Central Management System (Port MYS) versions 1.7.0 through 1.8.3-461, particularly those with exposed management interfaces or multi-tenant deployments where module access cannot be fully restricted.

Technical summary

CVE-2021-3855 is a command injection vulnerability (CWE-77) in Liman Central Management System's Port MYS product. The vulnerability affects HTTP/Controllers, CronMail, and Jobs modules in versions 1.7.0 through 1.8.3-462. An attacker with low privileges can exploit improper neutralization of special elements in commands to achieve high impact on confidentiality, integrity, and availability. The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network exploitable, low attack complexity, low privileges required, no user interaction, and high impacts across all three security dimensions.

Defensive priority

high

Recommended defensive actions

  • Upgrade to Liman Port MYS version 1.8.3-462 or later to remediate this vulnerability.
  • Review and restrict administrative access to HTTP/Controllers, CronMail, and Jobs modules as a defense-in-depth measure.
  • Monitor system logs for anomalous command execution patterns in affected modules.
  • Apply principle of least privilege to service accounts running Liman MYS components.

Evidence notes

CVE published 2023-03-01; modified 2026-05-18. Vendor advisory and Turkish government security advisories (USOM, siberguvenlik.gov.tr) confirm affected versions and provide mitigation guidance. CPE confirms version range 1.7.0 to before 1.8.3-462.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-3855 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-3855

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-3855 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3855

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.