Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21908

Опубликовано: 22 дек. 2021
Источник: nvd
CVSS3: 6
CVSS3: 6.5
CVSS2: 5.5
EPSS Низкий

Описание

Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [file] parameter (passed to the function as argv[1]), allowing an authenticated attacker to supply directory traversal primitives and delete semi-arbitrary files.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:garrett:ic_module_firmware:5.0:*:*:*:*:*:*:*
cpe:2.3:h:garrett:ic_module:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.0102
Низкий

6 Medium

CVSS3

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 6.5
github
около 4 лет назад

Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [file] parameter (passed to the function as argv[1]), allowing an authenticated attacker to supply directory traversal primitives and delete semi-arbitrary files.

EPSS

Процентиль: 77%
0.0102
Низкий

6 Medium

CVSS3

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-22
CWE-22