PatchSiren cyber security CVE debrief
CVE-2021-3855 Liman Central Management System CVE debrief
A command injection vulnerability in Liman Central Management System (Port MYS) allows authenticated attackers to execute arbitrary commands. The flaw exists in HTTP/Controllers, CronMail, and Jobs modules. Affected versions span 1.7.0 through 1.8.3-462. The vulnerability was disclosed in March 2023 with a CVSS 3.1 score of 8.8 (High severity).
- Vendor
- Liman Central Management System
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-03-01
- Original CVE updated
- 2026-05-18
- Advisory published
- 2023-03-01
- Advisory updated
- 2026-05-18
Who should care
Organizations running Liman Central Management System (Port MYS) versions 1.7.0 through 1.8.3-461, particularly those with exposed management interfaces or multi-tenant deployments where module access cannot be fully restricted.
Technical summary
CVE-2021-3855 is a command injection vulnerability (CWE-77) in Liman Central Management System's Port MYS product. The vulnerability affects HTTP/Controllers, CronMail, and Jobs modules in versions 1.7.0 through 1.8.3-462. An attacker with low privileges can exploit improper neutralization of special elements in commands to achieve high impact on confidentiality, integrity, and availability. The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network exploitable, low attack complexity, low privileges required, no user interaction, and high impacts across all three security dimensions.
Defensive priority
high
Recommended defensive actions
- Upgrade to Liman Port MYS version 1.8.3-462 or later to remediate this vulnerability.
- Review and restrict administrative access to HTTP/Controllers, CronMail, and Jobs modules as a defense-in-depth measure.
- Monitor system logs for anomalous command execution patterns in affected modules.
- Apply principle of least privilege to service accounts running Liman MYS components.
Evidence notes
CVE published 2023-03-01; modified 2026-05-18. Vendor advisory and Turkish government security advisories (USOM, siberguvenlik.gov.tr) confirm affected versions and provide mitigation guidance. CPE confirms version range 1.7.0 to before 1.8.3-462.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-3855 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-3855
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-3855 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3855
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://docs.liman.dev/baslangic/guvenlik
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0109
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0109
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.