PT-2021-21656 · Nch · Nch Ivm Attendant

Published

2021-07-25

·

Updated

2021-07-30

·

CVE-2021-37443

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions NCH IVM Attendant versions 5.12 and earlier
Description The issue allows path traversal via the logdeleteselected check0 parameter for file deletion.
Recommendations For versions 5.12 and earlier, consider restricting access to the logdeleteselected parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the check0 parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37443

Affected Products

Nch Ivm Attendant