PT-2021-23472 · Unknown · Siveillance Video Dlna Server

Published

2021-11-09

·

Updated

2022-07-25

·

CVE-2021-42021

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siveillance Video DLNA Server versions 2019 R1 through 2021 R1
Description The affected application contains a path traversal vulnerability that could allow an unauthenticated remote attacker to read arbitrary files on the server that are outside the application’s web document directory. This issue could be exploited to access sensitive information for subsequent attacks.
Recommendations For Siveillance Video DLNA Server versions 2019 R1 through 2021 R1, consider restricting access to sensitive files and directories on the server to minimize the risk of exploitation. As a temporary workaround, limit the application's ability to read files outside its web document directory until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42021

Affected Products

Siveillance Video Dlna Server