CVE-2021-38471

CRITICAL

Multiple API - Info Disclosure

Title source: llm
STIX 2.1

Description

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_confirm
https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01

Scores

CVSS v3 9.1
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
auvesy/versiondog < 8.0.0
Published Oct 22, 2021
Tracked Since Feb 18, 2026