Input validation error in Versiondog - CVE-2021-38455
Published: October 20, 2021
Vulnerability identifier: #VU57568
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38455
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected product’s OS Service does not verify any given parameter. A remote authenticated attacker can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.
Affected software
Versiondog
How to mitigate CVE-2021-38455
Install updates from vendor's website.
Versiondog - update to 8.0.0