CVE-2021-40845: Malicious File Upload
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40845?
CVE-2021-40845 is considered a high severity vulnerability due to the potential for remote code execution via improper file upload.
How do I fix CVE-2021-40845?
To fix CVE-2021-40845, upgrade Zenitel AlphaCom XE Audio Server to a version later than 11.2.3.10 that addresses this security flaw.
What impact does CVE-2021-40845 have on my system?
CVE-2021-40845 allows attackers to upload and execute malicious PHP code, which can compromise the integrity of the server.
What versions of Zenitel AlphaCom XE Audio Server are vulnerable to CVE-2021-40845?
Versions up to and including 11.2.3.10 of Zenitel AlphaCom XE Audio Server are vulnerable to CVE-2021-40845.
Is there a mitigation for CVE-2021-40845 if I cannot upgrade?
If you cannot upgrade, a temporary mitigation includes restricting access to the Custom Scripts section and regularly auditing uploaded files.