CVE-2021-40683
HIGHCVSS 7.8/10EPSS 0.42%
Last modified
CVE-2021-40683 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Akamai | Enterprise Application Access | < 2.3.1 |
| Akamai | Enterprise Application Access | >= 2.4.0, < 2.4.1 |
| Akamai | Enterprise Application Access | >= 2.5.0, < 2.5.3 |
References
- https://akamai.com/blog/news/eaa-client-escalation-of-privilege-vulnerabilityExploit, Vendor Advisory
- https://www.akamai.com/products/enterprise-application-accessProduct, Vendor Advisory
- https://akamai.com/blog/news/eaa-client-escalation-of-privilege-vulnerabilityExploit, Vendor Advisory
- https://www.akamai.com/products/enterprise-application-accessProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40683?
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
How severe is CVE-2021-40683?
CVE-2021-40683 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.42% probability of exploitation in the next 30 days.
How do I fix CVE-2021-40683?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-4067Use after free in window manager in Google Chrome on ChromeO…8.8
- CVE-2021-40670SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via th…9.8
- CVE-2021-40674An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 vi…9.8
- CVE-2021-40678In Piwigo 11.5.0, there exists a persistent cross-site scrip…5.4
- CVE-2021-4068Insufficient data validation in new tab page in Google Chrom…6.5
- CVE-2021-40680There is a Directory Traversal vulnerability in Artica Proxy…8.1
- CVE-2021-40684Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-0…9.1
- CVE-2021-4069vim is vulnerable to Use After Free7.8
- CVE-2021-40690All versions of Apache Santuario - XML Security for Java pri…7.5
- CVE-2021-40691A session hijack risk was identified in the Shibboleth authe…4.3
- CVE-2021-40692Insufficient capability checks made it possible for teachers…4.3
- CVE-2021-40693An authentication bypass risk was identified in the external…6.5
Are you affected by CVE-2021-40683?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
