CVE-2021-35380
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
Record summary
CVE-2021-35380 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBTermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)ExploitDB exploitby Fabiano GolluscioNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHTermTalk Server 3.24.0.2 - Local File InclusionCVSS 7.5
TermTalk Server (TTServer) 3.24.0.2 is vulnerable to file inclusion which allows unauthenticated malicious user to gain access to the files on the remote system by providing the relative path of the file they want to retrieve.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, including configuration files, credentials, and other sensitive data.
Remediation
Apply the latest patch or upgrade to a non-vulnerable version of TermTalk Server.
Source: ProjectDiscovery