CVE-2021-33178
Last modified
CVE-2021-33178 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nagvis | Nagvis | < 1.9.29 |
References
- https://nagvis.org/downloads/changelog/1.9.29Release Notes, Vendor Advisory
- https://www.synopsys.com/blogs/software-security/cyrc-advisory-nagios-xiThird Party Advisory
- https://nagvis.org/downloads/changelog/1.9.29Release Notes, Vendor Advisory
- https://www.synopsys.com/blogs/software-security/cyrc-advisory-nagios-xiThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33178?
How severe is CVE-2021-33178?
How do I fix CVE-2021-33178?
Are you affected by CVE-2021-33178?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
