Vulnerability Description
In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nascent | Remkon Device Manager | 4.0.0.0 |
Related Weaknesses (CWE)
References
- https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/ExploitThird Party Advisory
- https://www.nascent.com/single-post/2019/01/17/nascent-technology-releases-remkoVendor Advisory
- https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/ExploitThird Party Advisory
- https://www.nascent.com/single-post/2019/01/17/nascent-technology-releases-remkoVendor Advisory
FAQ
What is CVE-2021-38612?
CVE-2021-38612 is a vulnerability with a CVSS score of 7.5 (HIGH). In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.
How severe is CVE-2021-38612?
CVE-2021-38612 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38612?
Check the references section above for vendor advisories and patch information. Affected products include: Nascent Remkon Device Manager.