PT-2021-22804 · Squaredup · Squaredup For Scom
Published
2021-12-07
·
Updated
2021-12-07
·
CVE-2021-40095
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SquaredUp for SCOM version 5.2.1.6654
Description
An issue was discovered in the Download Log feature in System / Maintenance, which is susceptible to a local file inclusion vulnerability when processing remote input in the log files downloaded by an authenticated administrator user. This leads to the ability to read arbitrary files on the server filesystems.
Recommendations
For SquaredUp for SCOM version 5.2.1.6654, consider disabling the Download Log feature in System / Maintenance until a patch is available to prevent exploitation of the local file inclusion vulnerability. Restrict access to the System / Maintenance section to minimize the risk of exploitation. Avoid using the Download Log feature with remote input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squaredup For Scom