CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-20127

HIGH
8.1
CVSS Severity Score
EPSS Score0.1500%
EPSS Percentile35.32th
Published2021年10月13日
Last Modified2024年11月21日

Vulnerability Description

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.

Affected Platforms (CPE)

📦
Draytek

Vigorconnect

= 1.6.0

References & Advisories

関連する脆弱性情報