CVE-2021-31538

LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:lancom-systems:lcos_fx:10.5:-:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru1:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru2:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru3:*:*:*:*:*:*
OR cpe:2.3:h:lancom-systems:uf-160:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-260:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-500:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-60:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-910:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:05

Type Values Removed Values Added
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-010.txt - Exploit, Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-010.txt - Exploit, Third Party Advisory

22 Jun 2021, 20:44

Type Values Removed Values Added
References (MISC) https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-010.txt - (MISC) https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-010.txt - Exploit, Third Party Advisory
CPE cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru2:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru1:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:-:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-60:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-910:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-160:-:*:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-260:-:*:*:*:*:*:*:*
cpe:2.3:o:lancom-systems:lcos_fx:10.5:ru3:*:*:*:*:*:*
cpe:2.3:h:lancom-systems:uf-500:-:*:*:*:*:*:*:*
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

10 Jun 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-10 15:15

Updated : 2024-11-21 06:05


NVD link : CVE-2021-31538

Mitre link : CVE-2021-31538

CVE.ORG link : CVE-2021-31538


JSON object : View

Products Affected

lancom-systems

  • lcos_fx
  • uf-910
  • uf-60
  • uf-500
  • uf-160
  • uf-260
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')