CyberSec.Space Logo
Back to CVE Browser

CVE-2021-40870

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score47.3760%
EPSS Percentile95.37th
PublishedSep 13, 2021
Last ModifiedNov 10, 2025

Vulnerability Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Affected Platforms (CPE)

πŸ“¦
Aviatrix

Controller

>= 6.2 and < 6.2.2043
πŸ“¦
Aviatrix

Controller

>= 6.3 and < 6.3.2490
πŸ“¦
Aviatrix

Controller

>= 6.4 and < 6.4.2838
πŸ“¦
Aviatrix

Controller

>= 6.5 and < 6.5.1922

References & Advisories

Related Vulnerabilities