CVE-2021-35962
Summary
| CVE | CVE-2021-35962 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-16 16:15:00 UTC |
| Updated | 2021-08-02 17:33:00 UTC |
| Description | Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Secom | Door Access Control | All | All | All | All |
| Application | Secom | Personnel Attendance System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TWCERT/CC台灣電腦網路危機處理暨協調中心-中興保全Dr.ID 門禁考勤系統 - Path Traversal | MISC | www.twcert.org.tw | |
| CVE-2021-35962|中華資安國際 CHT Security Co., Ltd. | MISC | www.chtsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.