MEDIUM · 4.9

CVE-2021-40858

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

Vulnerability Description

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AuerswaldCompact 5500R Ip Firmware<= 8.0b
AuerswaldCompact 5500R Ip-
AuerswaldCompact 5200R Ip Firmware<= 8.0b
AuerswaldCompact 5200R Ip-
AuerswaldCompact 5000R Ip Firmware<= 8.0b
AuerswaldCompact 5000R Ip-
AuerswaldCompact 4000 Ip Firmware<= 8.0b
AuerswaldCompact 4000R Ip-
AuerswaldCommander 6000R Ip Firmware<= 8.0b
AuerswaldCommander 6000R Ip-
AuerswaldCommander 6000Rx Ip Firmware<= 8.0b
AuerswaldCommander 6000Rx Ip-
AuerswaldCommander Business\(19\"\) Ip Firmware<= 8.0b
AuerswaldCommander Business\(19\"\) Ip-
AuerswaldCommander Basic.2\(19\"\) Ip Firmware<= 8.0b
AuerswaldCommander Basic.2\(19\"\) Ip-
AuerswaldCompact 5010 Voip Ip Firmware<= 8.0b
AuerswaldCompact 5010 Voip Ip-
AuerswaldCompact 5020 Voip Ip Firmware<= 8.0b
AuerswaldCompact 5020 Voip Ip-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-40858?

CVE-2021-40858 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

How severe is CVE-2021-40858?

CVE-2021-40858 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-40858?

Check the references section above for vendor advisories and patch information. Affected products include: Auerswald Compact 5500R Ip Firmware, Auerswald Compact 5500R Ip, Auerswald Compact 5200R Ip Firmware, Auerswald Compact 5200R Ip, Auerswald Compact 5000R Ip Firmware.