Record summary

CVE-2021-45967 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 20, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPascom CPS Server-Side Request ForgeryCVSS 9.8

Pascom versions before 7.20 packaged with Cloud Phone System contain a known server-side request forgery vulnerability.

Impact

The vulnerability can result in unauthorized access to sensitive data or systems, potentially leading to further exploitation or compromise.

Remediation

Apply the latest security patches or updates provided by Pascom to fix the Server-Side Request Forgery vulnerability (CVE-2021-45967).

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscvecve2021pascomssrfpascom_cloud_phone_systemvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:pascom:cloud_phone_system:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5