CVE-2021-40870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
13/09/2021
Last modified:
03/04/2025

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* 6.2 (including) 6.2.2043 (excluding)
cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* 6.3 (including) 6.3.2490 (excluding)
cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* 6.4 (including) 6.4.2838 (excluding)
cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* 6.5 (including) 6.5.1922 (excluding)