CVE-2021-3832: Integria IMS Remote Code Execution
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
To reduce exposure while upgrading, restrict access to Integria IMS file upload functionality (e.g., limit which users/sources can reach the upload endpoint) so unauthenticated attackers cannot abuse AsyncUpload().
Event History
Frequently Asked Questions
What is CVE-2021-3832?
CVE-2021-3832 is a vulnerability in Integria IMS version 5.0.92 that allows remote code execution through file uploading.
How severe is CVE-2021-3832?
CVE-2021-3832 has a severity rating of 9.8 out of 10, which is classified as critical.
How does CVE-2021-3832 affect Integria IMS?
CVE-2021-3832 affects Integria IMS version 5.0.92 and can be exploited by an unauthenticated attacker to execute remote code through file uploading.
Is there a fix available for CVE-2021-3832?
Yes, you should update Integria IMS to a version that is not affected by CVE-2021-3832.
Where can I find more information about CVE-2021-3832?
You can find more information about CVE-2021-3832 at the following references: [1] [2]