CVE-2021-35975

Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
systematicafinancial_calculator
𝑥
≤ 1.3.05
systematicafix_adapter
𝑥
≤ 2.4.0.25
systematicahttp_adapter
𝑥
≤ 1.8.0.15
systematicamssql_messagebus_proxy
𝑥
≤ 1.1.06
systematicaradius
𝑥
≤ 3.9.256.777
systematicasmtp_adapter
𝑥
≤ 2.0.1.101
𝑥
= Vulnerable software versions