CVE-2021-42021
A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020 R3), Siveillance Video DLNA Server (2021 R1). The affected application contains a path traversal vulnerability that could allow to read arbitrary files on the server that are outside the application’s web document directory. An unauthenticated remote attacker could exploit this issue to access sensitive information for subsequent attacks.
EPSS 0.99% · 77.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| siemens | siveillance_video_management_software_2019_r2 | |
| siemens | siveillance_video_management_software_2019_r1 | |
| Siemens | Siveillance Video DLNA Server | 2019 R2, 2019 R3, 2020 R2 |
| siemens | siveillance_video_management_software_2020_r1 | |
| siemens | siveillance_video_management_software_2020_r2 | |
| siemens | siveillance_video_management_software_2019_r3 |
Timeline
- Nov 9, 2021 CVE Published
- Nov 10, 2021 EPSS Score
- Jan 4, 2022 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 25, 2022 EPSS Score
- Jun 20, 2022 EPSS Score
- Aug 15, 2022 EPSS Score
- Dec 4, 2022 EPSS Score
- Jan 29, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-755517.pdf url
- https://cert-portal.siemens.com/productcert/pdf/ssa-248289.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-703715.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-840188.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-362164.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-328042.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-917476.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-114589.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-201384.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-537983.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-779699.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-580693.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-185699.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-740908.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-145157.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-338732.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-42021 advisory