Record summary

CVE-2021-33558 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs and 1 Nuclei template. VulnCheck reports CVE-2021-33558 use in known ransomware campaigns.

Description

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubmdanzaruddin/CVE-2021-33558.Repository PoCby mdanzaruddinStars: 3Not analyzed2 files

1.5 KiB

GitHub

PoC details
GitHubanldori/CVE-2021-33558Repository PoCby anldoriStars: 1Not analyzed1 file

471 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHBoa 0.94.13 - Information DisclosureCVSS 7.5

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa.

Impact

Unauthenticated attackers can access sensitive JavaScript files exposing logging functionality and potentially other configuration details.

Remediation

Update Boa web server to a version newer than 0.94.13 or apply vendor security patches.

AuthorsDhiyaneshDK
Template tagscvecve2021boainfo-leakvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:boa:boa:0.94.13:*:*:*:*:*:*:*
Shodan: Server: Boa/0.94.13
FOFA: Server: Boa/0.94.13

Source: ProjectDiscovery

References

4