CRITICAL

CVE-2021-40870

Aviatrix Controller 2021-09-13 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Summary dbcve.org

Aviatrix Controller versions 6.x prior to 6.5-1804.1922 contain an unrestricted file upload vulnerability that allows unauthenticated attackers to upload files to arbitrary locations on the system via directory traversal. The uploaded files can be of dangerous types (e.g., executable scripts), leading to remote code execution on the affected controller.

Mitigation

Upgrade Aviatrix Controller to version 6.5-1804.1922 or later. If immediate patching is not possible, restrict network access to the Controller management interface and implement WAF rules to detect and block directory traversal and file upload attacks.

Proof of Concept

Weakness (CWE)

CWE-23

EPSS Score

93.02%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE