CVE-2021-40870Aviatrix Controller Unrestricted Upload of File

PUBLISHEDvulnerability record
2022-01-18 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-40870
Project:
Aviatrix
Product:
Aviatrix Controller
Date Added:
2022-01-18
Due Date:
2022-02-01
Last Updated:
June 21, 2025

Vulnerability Name

Aviatrix Controller Unrestricted Upload of File

Description

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses