CVE-2021-40870
Description
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Summary dbcve.org
Aviatrix Controller versions 6.x prior to 6.5-1804.1922 contain an unrestricted file upload vulnerability that allows unauthenticated attackers to upload files to arbitrary locations on the system via directory traversal. The uploaded files can be of dangerous types (e.g., executable scripts), leading to remote code execution on the affected controller.
Mitigation
Upgrade Aviatrix Controller to version 6.5-1804.1922 or later. If immediate patching is not possible, restrict network access to the Controller management interface and implement WAF rules to detect and block directory traversal and file upload attacks.