CVE-2017-8921 is a directory traversal vulnerability in FlightGear versions prior to 2017.2.1, specifically within the FGCommand interface. This flaw allows a remote attacker to overwrite user-writable files with FlightGear flightplan XML data, potentially damaging user files through a malicious third-party aircraft. Rated with a CVSS score of 7.5 (HIGH), it has a network attack vector and low attack complexity, but does not impact confidentiality or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2017.2CPE matchmatch criteria | cpe:2.3:a:flightgear:flightgear:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.