CVE-2021-38471 Vulnerability Details
/
/
/
CVE-2021-38471 Metadata Quick Info
CVE Published: 22/10/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021
Source: icscert |
Vendor: AUVESY |
Product: Versiondog
Status : PUBLISHED
CVE-2021-38471 Description
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.
Metrics
CVSS Version: 3.1 |
Base Score: 9.1 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* NONE
Integrity Impact (I)* HIGH
Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-434
CWE Name: CWE-434 Unrestricted Upload of File with Dangerous Type
Source: AUVESY
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).