ZeroHour

CVE-2021-40870

KEV PoC ×2moderate

Unauthenticated File-Upload RCE via Path Traversal in Aviatrix Controller 6.x

CISA: Aviatrix Controller Unrestricted Upload of File

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

CVE-2021-40870 is an unrestricted file-upload flaw (CWE-23) in the Aviatrix Controller, affecting 6.x releases before 6.5-1804.1922, which scores a critical 9.8 because it requires no authentication, no user interaction, and is reachable over the network. An unauthenticated attacker sends a crafted upload request whose filename or path includes directory-traversal sequences and a dangerous file type, letting them write files outside the intended directory — including executable content — onto the controller host. Successful exploitation yields arbitrary code execution on the controller, the central management component of Aviatrix's cloud networking platform, which could give an attacker control of network orchestration and a foothold to pivot into connected cloud and on-premises environments. Any organization running an affected Aviatrix Controller version is at risk, with the highest exposure where the controller's management interface is reachable from the internet. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-01-18, public proof-of-concept code exists, and EPSS estimates a 93% probability of exploitation within 30 days.

What to do: Upgrade the Aviatrix Controller to 6.5-1804.1922 or later per the vendor's instructions, as required by CISA's KEV catalog. Until patched, restrict access to the controller's management interface (firewall/allow-list, VPN, or keep it off the public internet) and review the host for signs of compromise such as unexpected uploaded files, web shells, or unfamiliar processes, since ransomware use remains unknown.

Affected
Aviatrix Controller6.x before 6.5-1804.1922
Estimated exposure
moderate≈ a few thousand internet-exposed Aviatrix Controllers (public scans in early 2022 showed thousands of exposed controller web interfaces) — Aviatrix Controllers are typically deployed one per customer environment for cloud network orchestration, and internet-wide scans around the KEV listing period surfaced on the order of thousands of exposed controller management interfaces…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

CISA Known Exploited Vulnerability
Affected
Aviatrix Aviatrix Controller
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
aviatrix
Products
controller
Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news