{"api_version":"1","generated_at":"2026-07-24T00:04:27+00:00","cve":"CVE-2021-38465","urls":{"html":"https://cve.report/CVE-2021-38465","api":"https://cve.report/api/cve/CVE-2021-38465.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-38465","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-38465"},"summary":{"title":"CVE-2021-38465","description":"The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2021-10-22 12:15:00","updated_at":"2022-10-27 16:36:00"},"problem_types":["CWE-770"],"metrics":[],"references":[{"url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01","name":"https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01","refsource":"CONFIRM","tags":[],"title":"AUVESY Versiondog | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-38465","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38465","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Amir Preminger of Claroty reported these vulnerabilities to CISA.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"38465","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"auvesy","cpe5":"versiondog","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-38465","qid":"590588","title":"AUVESY Versiondog Multiple Vulnerabilities (ICSA-21-292-01)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","DATE_PUBLIC":"2021-08-19T15:34:00.000Z","ID":"CVE-2021-38465","STATE":"PUBLIC","TITLE":"AUVESY Versiondog "},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Versiondog","version":{"version_data":[{"version_affected":"<=","version_name":"All","version_value":"8.0"}]}}]},"vendor_name":"AUVESY"}]}},"credit":[{"lang":"eng","value":"Amir Preminger of Claroty reported these vulnerabilities to CISA."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-400 Uncontrolled Resource Consumption"}]}]},"references":{"reference_data":[{"name":"https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01","refsource":"CONFIRM","url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01"}]},"solution":[{"lang":"eng","value":"AUVESY recommends upgrading Versiondog to Version 8.1 or later (login required)."}],"source":{"advisory":"https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-10-22 12:15:00","lastModifiedDate":"2022-10-27 16:36:00","problem_types":["CWE-770"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:auvesy:versiondog:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"38465","Ordinal":"214127","Title":"CVE-2021-38465","CVE":"CVE-2021-38465","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"38465","Ordinal":"1","NoteData":"The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"38465","Ordinal":"2","NoteData":"2021-10-22","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"38465","Ordinal":"3","NoteData":"2021-10-22","Type":"Other","Title":"Modified"}]}}}