CVE-2021-40870
KEV PoC ×2moderateUnauthenticated File-Upload RCE via Path Traversal in Aviatrix Controller 6.x
CISA: Aviatrix Controller Unrestricted Upload of File
CVE-2021-40870 is an unrestricted file-upload flaw (CWE-23) in the Aviatrix Controller, affecting 6.x releases before 6.5-1804.1922, which scores a critical 9.8 because it requires no authentication, no user interaction, and is reachable over the network. An unauthenticated attacker sends a crafted upload request whose filename or path includes directory-traversal sequences and a dangerous file type, letting them write files outside the intended directory — including executable content — onto the controller host. Successful exploitation yields arbitrary code execution on the controller, the central management component of Aviatrix's cloud networking platform, which could give an attacker control of network orchestration and a foothold to pivot into connected cloud and on-premises environments. Any organization running an affected Aviatrix Controller version is at risk, with the highest exposure where the controller's management interface is reachable from the internet. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-01-18, public proof-of-concept code exists, and EPSS estimates a 93% probability of exploitation within 30 days.
What to do: Upgrade the Aviatrix Controller to 6.5-1804.1922 or later per the vendor's instructions, as required by CISA's KEV catalog. Until patched, restrict access to the controller's management interface (firewall/allow-list, VPN, or keep it off the public internet) and review the host for signs of compromise such as unexpected uploaded files, web shells, or unfamiliar processes, since ransomware use remains unknown.
| Aviatrix Controller | 6.x before 6.5-1804.1922 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
- Affected
- Aviatrix Aviatrix Controller
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- aviatrix
- Products
- controller
- Weakness
- CWE-23
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H