CISA Known Exploited Vulnerability

CVE-2021-40870

Aviatrix · Aviatrix Controller

Aviatrix Controller Unrestricted Upload of File

Date added
BOD 22-01 due date
CWE CWE-25, CWE-96
Ransomware Unknown

CISA description

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Required action

Apply updates per vendor instructions.