CVE-2021-40870—Aviatrix Controller Unrestricted Upload of File
PUBLISHEDvulnerability record
2022-01-18 · last modified June 21, 2025
Metadata
Vulnerability Name
Aviatrix Controller Unrestricted Upload of File
Description
Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.