6.8
CVSSv2

CVE-2021-40858

Published: 13/12/2021 Updated: 04/01/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

Auerswald COMpact 5500R devices prior to 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

auerswald compact_5500r_ip_firmware

auerswald compact_5200r_ip_firmware

auerswald compact_5000r_ip_firmware

auerswald compact_4000_ip_firmware

auerswald commander_6000r_ip_firmware

auerswald commander_6000rx_ip_firmware

auerswald commander_business\\(19\\\"\\)_ip_firmware

auerswald commander_basic.2\\(19\\\"\\)_ip_firmware

auerswald compact_5010_voip_ip_firmware

auerswald compact_5020_voip_ip_firmware

Exploits

RedTeam Pentesting discovered a vulnerability in the web-based management interface of the Auerswald COMpact 5500R PBX which allows users with the "sub-admin" privilege to access any files on the PBX's file system Versions 80B and below are affected ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [RT-SA-2021-006] Auerswald COMpact Arbitrary File Disclosure <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fr ...