Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42021

Опубликовано: 09 нояб. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020 R3), Siveillance Video DLNA Server (2021 R1). The affected application contains a path traversal vulnerability that could allow to read arbitrary files on the server that are outside the application’s web document directory. An unauthenticated remote attacker could exploit this issue to access sensitive information for subsequent attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:siemens:siveillance_video_management_software_2019_r1:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_video_management_software_2019_r2:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_video_management_software_2019_r3:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_video_management_software_2020_r1:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_video_management_software_2020_r2:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:siveillance_video_dlna_server:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.00995
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-26
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020 R3), Siveillance Video DLNA Server (2021 R1). The affected application contains a path traversal vulnerability that could allow to read arbitrary files on the server that are outside the application’s web document directory. An unauthenticated remote attacker could exploit this issue to access sensitive information for subsequent attacks.

EPSS

Процентиль: 77%
0.00995
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-26
CWE-22