CVE-2021-35380
Summary
| CVE | CVE-2021-35380 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-15 22:15:00 UTC |
| Updated | 2022-04-25 14:10:00 UTC |
| Description | A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore). |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solari | Termtalk Server | 3.24.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Disclosure - Solari di Udine - Swascan | MISC | www.swascan.com | Third Party Advisory |
| Security Blog - Swascan | MISC | www.swascan.com | Third Party Advisory |
| TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated) - Windows remote Exploit | MISC | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.