Input validation error in Versiondog - CVE-2021-38455

 

Input validation error in Versiondog - CVE-2021-38455

Published: October 20, 2021


Vulnerability identifier: #VU57568
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38455
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product’s OS Service does not verify any given parameter. A remote authenticated attacker can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.


Affected software

Versiondog

How to mitigate CVE-2021-38455

Install updates from vendor's website.

Versiondog - update to 8.0.0

External References

Related Security Bulletins