Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

Project Subscriptions

Vendors Products
Auerswald Subscribe
Commander 6000r Ip Subscribe
Commander 6000r Ip Firmware Subscribe
Commander 6000rx Ip Subscribe
Commander 6000rx Ip Firmware Subscribe
Commander Basic.2\(19\"\) Ip Subscribe
Commander Basic.2\(19\"\) Ip Firmware Subscribe
Commander Business\(19\"\) Ip Subscribe
Commander Business\(19\"\) Ip Firmware Subscribe
Compact 4000 Ip Firmware Subscribe
Compact 4000r Ip Subscribe
Compact 5000r Ip Subscribe
Compact 5000r Ip Firmware Subscribe
Compact 5010 Voip Ip Subscribe
Compact 5010 Voip Ip Firmware Subscribe
Compact 5020 Voip Ip Subscribe
Compact 5020 Voip Ip Firmware Subscribe
Compact 5200r Ip Subscribe
Compact 5200r Ip Firmware Subscribe
Compact 5500r Ip Subscribe
Compact 5500r Ip Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-28014 Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T02:51:07.770Z

Reserved: 2021-09-10T00:00:00

Link: CVE-2021-40858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-13T04:15:07.087

Modified: 2024-11-21T06:24:57.007

Link: CVE-2021-40858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses