First published: Wed Feb 23 2022(Updated: )
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Credit: cve_disclosure@tech.gov.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=11.0.0<11.8.8 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=12.0.0<12.13.0 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42854 is a vulnerability discovered in the SteelCentral AppInternals Dynamic Sampling Agent's PluginServlet, which allows directory traversal attacks.
CVE-2021-42854 has a severity rating of critical with a score of 9.8.
Riverbed SteelCentral AppInternals Dynamic Sampling Agent versions from 10.0.0 to 12.13.0 are affected by CVE-2021-42854.
CVE-2021-42854 allows a malicious payload to be executed through directory traversal vulnerabilities in the /api/appInternals/1.0/plugin/pmx API.
Yes, please refer to the reference link provided for information on how to fix CVE-2021-42854.