CVE-2021-42853: Directory Traversal Delete/Read at AgentDiagnosticServlet
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42853?
CVE-2021-42853 is a directory traversal vulnerability in the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet API.
What is the severity of CVE-2021-42853?
The severity of CVE-2021-42853 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2021-42853?
The Riverbed Steelcentral Appinternals Dynamic Sampling Agent versions 10.0.0 to 11.8.8 and versions 12.0.0 to 12.13.0 are affected by CVE-2021-42853.
How can an attacker exploit CVE-2021-42853?
An attacker can exploit CVE-2021-42853 by performing directory traversal attacks on the "/api/appInternals/1.0/agent/diagnostic/logs" API.
Is there a fix for CVE-2021-42853?
Patch your Riverbed Steelcentral Appinternals Dynamic Sampling Agent to a version outside the vulnerable ranges specified in the CVE.