CVE-2021-31926
Last modified
CVE-2021-31926 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission to make changes to the system's network configuration).. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission to make changes to the system's network configuration).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cubecoders | Amp | >= 2.1.0, < 2.1.1.2 |
References
- https://github.com/CubeCoders/AMP/issues/443Exploit, Third Party Advisory
- https://github.com/CubeCoders/AMP/issues/443Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31926?
How severe is CVE-2021-31926?
How do I fix CVE-2021-31926?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31920Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exp…6.5
- CVE-2021-31921Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotel…9.8
- CVE-2021-31922An HTTP Request Smuggling vulnerability in Pulse Secure Virt…7.5
- CVE-2021-31923Ping Identity PingAccess before 5.3.3 allows HTTP request sm…5.3
- CVE-2021-31924Yubico pam-u2f before 1.1.1 has a logic issue that, dependin…6.8
- CVE-2021-31925Pexip Infinity 25.x before 25.4 has Improper Input Validatio…7.5
- CVE-2021-31927An Insecure Direct Object Reference (IDOR) vulnerability in …4.3
- CVE-2021-31928Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a…8.8
- CVE-2021-31929Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a…4.3
- CVE-2021-3193Improper access and command validation in the Nagios Docker …9.8
- CVE-2021-31930Persistent cross-site scripting (XSS) in the web interface o…6.1
- CVE-2021-31932Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows…9.8
Are you affected by CVE-2021-31926?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
