CVE-2021-40870
13.09.2021, 08:15
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.Enginsight
Vendor | Product | Version |
---|---|---|
aviatrix | controller | 6.2 ≤ 𝑥 < 6.2.2043 |
aviatrix | controller | 6.3 ≤ 𝑥 < 6.3.2490 |
aviatrix | controller | 6.4 ≤ 𝑥 < 6.4.2838 |
aviatrix | controller | 6.5 ≤ 𝑥 < 6.5.1922 |
𝑥
= Vulnerable software versions
References