PT-2022-10165 · Agg · Agg Software Web Server

Michael Heinzl

·

Published

2022-05-24

·

Updated

2023-07-07

·

CVE-2021-32964

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AGG Software Web Server versions 4.0.40.1014 and prior
Description The issue allows an attacker to perform a path traversal attack, potentially enabling them to read arbitrary files from the file system.
Recommendations For AGG Software Web Server versions 4.0.40.1014 and prior, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, limit the web server's ability to access arbitrary files from the file system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-32964

Affected Products

Agg Software Web Server