CVE-2021-40683

HIGH

Akamai EAA Client <2.3.1-2.5.3 - Path Traversal

Title source: llm
STIX 2.1

Description

In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 21.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
akamai/enterprise_application_access < 2.3.1
Published Oct 04, 2021
Tracked Since Feb 18, 2026