CVE-2021-40870
CRITICAL KEV NUCLEIAviatrix Controller <6.5-1804.1922 - Code Injection
Title source: llmDescription
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Exploits (6)
nomisec
WORKING POC
by System00-Security · remote
https://github.com/System00-Security/CVE-2021-40870
Nuclei Templates (1)
Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution
CRITICALby pikpikcu
Shodan:
http.title:"aviatrix cloud controller"
FOFA:
title="aviatrix cloud controller"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9426
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-01-18
VulnCheck KEV
2021-12-21
InTheWild.io
2021-12-21
ENISA EUVD
EUVD-2021-28025
CWE
CWE-23
Status
published
Products (1)
aviatrix/controller
6.2 - 6.2.2043
Published
Sep 13, 2021
KEV Added
Jan 18, 2022
Tracked Since
Feb 18, 2026