Skip to content
COOEY

EXPOSURES › CVE-2021-40870

CVE-2021-40870

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-40870 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

An unauthenticated user could upload a dangerous file to the Aviatrix Controller, leading to arbitrary code execution via directory traversal.

The Aviatrix Controller allowed unauthenticated users to upload files with dangerous types, enabling arbitrary code execution through directory traversal. This failure is critical for DIB organizations because it represents a severe, avoidable vulnerability that could lead to full system compromise and data breaches. Organizations should ensure all their cloud networking solutions are patched and monitored for similar upload vulnerabilities.

Shame score — The vulnerability allowed unauthenticated remote code execution, which is a severe, avoidable flaw that could have been exploited by any attacker without needing prior access.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.