ZeroHour

CVE-2021-29101

CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

Vendors
esri
Products
arcgis geoevent server
Weakness
CWE-23, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.