First published: Thu Jun 10 2021(Updated: )
LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lancom Systems LCOS | =10.5 | |
Lancom Systems LCOS | =10.5-ru1 | |
Lancom Systems LCOS | =10.5-ru2 | |
Lancom Systems LCOS | =10.5-ru3 | |
Lancom-systems Uf-160 | ||
Lancom Systems UF-260 | ||
Lancom Systems UF-500 | ||
Lancom Systems UF-60 | ||
Lancom-systems Uf-910 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31538 is categorized as a high-severity vulnerability due to its potential for unauthorized access via relative path traversal.
To fix CVE-2021-31538, update the LANCOM R&S Unified Firewall devices to the latest version of LCOS FX that addresses this vulnerability.
CVE-2021-31538 affects LANCOM R&S Unified Firewall devices running LCOS FX version 10.5 including all its revisions.
Relative path traversal in CVE-2021-31538 allows attackers to access files and directories outside the intended file system path.
Yes, remote exploitation is possible with CVE-2021-31538 if proper mitigations are not in place.