CVE-2021-33576: Path Traversal
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33576?
CVE-2021-33576 is rated as a medium severity vulnerability due to its potential impact on file system integrity.
How does CVE-2021-33576 work?
CVE-2021-33576 allows attackers to exploit path-traversal characters in a specified filename within AS2 messages to write files to arbitrary locations on disk.
What software versions are affected by CVE-2021-33576?
CVE-2021-33576 affects Cleo LexiCom version 5.5.0.0.
How do I fix CVE-2021-33576?
To mitigate CVE-2021-33576, update to a patched version of Cleo LexiCom that addresses the path-traversal vulnerability.
What are the risks of not addressing CVE-2021-33576?
If CVE-2021-33576 is not addressed, attackers could potentially overwrite or access sensitive files on the server.