Path traversal in Luxion products - CVE-2021-22651
Published: February 8, 2021
Vulnerability identifier: #VU50419
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22651
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and store arbitrary scripts into automatic startup folders.
Affected software
KeyShot
KeyShot Viewer
KeyVR
KeyShot Network Rendering
KeyShot Viewer
KeyVR
KeyShot Network Rendering
How to mitigate CVE-2021-22651
Install updates from vendor's website.
KeyShot - update to 10.1
KeyShot Viewer - update to 10.1
KeyShot Network Rendering - update to 10.1
KeyVR - update to 10.1
KeyShot Viewer - update to 10.1
KeyShot Network Rendering - update to 10.1
KeyVR - update to 10.1