7.5
CVSSv2

CVE-2021-40870

Published: 13/09/2021 Updated: 08/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Aviatrix Controller 6.x prior to 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aviatrix controller

Github Repositories

Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code

CVE-2021-40870 Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code attackerkbcom/assessments/970a9fa9-223d-4d07-bafa-a338147934f3

Aviatrix allows an authenticated user to execute arbitrary code

CVE-2021-40870 Aviatrix allows an authenticated user to execute arbitrary code

Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file which allows an unauthenticated user to execute arbitrary code via directory traversal

CVE-2021-40870 Exploitation An issue was discovered in Aviatrix Controller 6x before 65-18041922 Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal Modules need to Install To run this project, you will need to add the following modules in your python requests urllib3 Us