CVE-2021-27236

CRITICAL

Mutare Voice <3.3.8 - RCE

Title source: llm

Description

An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.

Scores

CVSS v3 9.8
EPSS 0.0190
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-668
Status published

Affected Products (1)

mutare/voice < 3.3.8

Timeline

Published Feb 16, 2021
Tracked Since Feb 18, 2026