CVE-2021-40870 is a critical vulnerability affecting Aviatrix Controller 6.x before version 6.5-1804.1922, allowing unauthenticated attackers to upload dangerous file types and execute arbitrary code via directory traversal. This vulnerability has a CVSS score of 9.8, indicating a severe risk with low attack complexity and complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has publicly available Nuclei templates for remote command execution. The high EPSS score and significant community discussion further underscore its immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2, < 6.2.2043CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 6.3, < 6.3.2490CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 6.4, < 6.4.2838CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* | ||
>= 6.5, < 6.5.1922CPE matchmatch criteria | cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.