CVE-2021-33558 describes an information disclosure vulnerability in Boa 0.94.13, potentially allowing remote attackers to access sensitive data through misconfigured files like backup.html and config.js. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, leading to a high impact on confidentiality. Although some reports suggest it's a site-specific issue rather than a core Boa vulnerability, its high EPSS score and FAUCET Risk Score of 99/100 indicate significant exploitability. While not in the KEV catalog, it has garnered substantial community discussion and media coverage, with reports of hackers targeting it in power grid attacks, and Nuclei templates are available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.94.13CPE matchmatch criteria | cpe:2.3:a:boa:boa:0.94.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.