CVE-2021-32093: Medium severity sonicwall nsa emissary vulnerability
Published May 7, 2021
·Updated
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter.
Affected Software
1 affected component
NSA Emissary=5.9.0
Event History
May 7, 2021
CVE Published
via MITRE·03:52 AM
Data Sourced
via MITRE·03:52 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-32093?
CVE-2021-32093 is designated as a medium severity vulnerability.
2
How do I fix CVE-2021-32093?
To fix CVE-2021-32093, upgrade the NSA Emissary application to a version that has patched this vulnerability.
3
What type of attack does CVE-2021-32093 enable?
CVE-2021-32093 enables an authenticated user to read arbitrary files on the server, leading to potential information disclosure.
4
Who is affected by CVE-2021-32093?
Users of the NSA Emissary version 5.9.0 are affected by CVE-2021-32093.
5
What component is involved in CVE-2021-32093?
The ConfigFileAction component is involved in the vulnerability CVE-2021-32093.