CVE-2021-27236

CRITICAL

Mutare Voice 3.0.0-3.3.7 - Unauthenticated Local File Inclusion and Remote Code Execution via getfile.asp

Title source: llm
STIX 2.1

Description

An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0206
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-668
Status published
Products (1)
mutare/voice 3.0.0 - 3.3.8
Published Feb 16, 2021
Tracked Since Feb 18, 2026