CVE-2021-45967
pascom cloud_phone_system Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2021-45967 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 20, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
cloud_phone_systemBrowse pascom / cloud_phone_system | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPascom CPS Server-Side Request ForgeryCVSS 9.8
Pascom versions before 7.20 packaged with Cloud Phone System contain a known server-side request forgery vulnerability.
Impact
The vulnerability can result in unauthorized access to sensitive data or systems, potentially leading to further exploitation or compromise.
Remediation
Apply the latest security patches or updates provided by Pascom to fix the Server-Side Request Forgery vulnerability (CVE-2021-45967).
Source: ProjectDiscovery