CVE-2021-31538: Path Traversal
Published Jun 10, 2021
·Updated
LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
Affected Software
9 affected components
Lancom-systems Lcos Fx=10.5
Lancom-systems Lcos Fx=10.5-ru1
Lancom-systems Lcos Fx=10.5-ru2
Lancom-systems Lcos Fx=10.5-ru3
Lancom-systems Uf-160
Lancom-systems Uf-260
Lancom-systems Uf-500
Lancom-systems Uf-60
Lancom-systems Uf-910
Event History
Jun 10, 2021
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-31538?
CVE-2021-31538 is categorized as a high-severity vulnerability due to its potential for unauthorized access via relative path traversal.
2
How do I fix CVE-2021-31538?
To fix CVE-2021-31538, update the LANCOM R&S Unified Firewall devices to the latest version of LCOS FX that addresses this vulnerability.
3
Which devices are affected by CVE-2021-31538?
CVE-2021-31538 affects LANCOM R&S Unified Firewall devices running LCOS FX version 10.5 including all its revisions.
4
What is relative path traversal in the context of CVE-2021-31538?
Relative path traversal in CVE-2021-31538 allows attackers to access files and directories outside the intended file system path.
5
Is remote exploitation possible with CVE-2021-31538?
Yes, remote exploitation is possible with CVE-2021-31538 if proper mitigations are not in place.