Junglewise Threat Intelligence

CVE-2021-40870: Aviatrix Controller Unrestricted Upload of File

CVE-2021-40870 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-18

Executive brief

Aviatrix Controller allows unauthenticated remote code execution due to unrestricted file uploads. An attacker can utilize directory traversal to upload dangerous file types to sensitive locations on the controller.

Affected products

  • Aviatrix Controller 6.x before 6.5-1804.1922

Timeline

  • 2021-09-11: disclosed: Vendor security note published
  • 2021-09-13: disclosed: NVD Published Date
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-09-13: exploited: Reported as exploited in the wild per CISA KEV entry date