PT-2021-22804 · Squaredup · Squaredup For Scom

Published

2021-12-07

·

Updated

2021-12-07

·

CVE-2021-40095

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SquaredUp for SCOM version 5.2.1.6654
Description An issue was discovered in the Download Log feature in System / Maintenance, which is susceptible to a local file inclusion vulnerability when processing remote input in the log files downloaded by an authenticated administrator user. This leads to the ability to read arbitrary files on the server filesystems.
Recommendations For SquaredUp for SCOM version 5.2.1.6654, consider disabling the Download Log feature in System / Maintenance until a patch is available to prevent exploitation of the local file inclusion vulnerability. Restrict access to the System / Maintenance section to minimize the risk of exploitation. Avoid using the Download Log feature with remote input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-40095

Affected Products

Squaredup For Scom