Unquoted Path Vulnerability in Akamai EAA Client
CVE-2021-40683

7.8HIGH

Key Information:

Vendor

Akamai

Vendor
CVE Published:
4 October 2021

What is CVE-2021-40683?

The Akamai EAA Client is susceptible to an internal security issue where an unquoted path can be exploited, enabling an attacker to hijack the flow of execution. This flaw affects multiple versions of the software, including those prior to 2.3.1, versions in the 2.4.x range before 2.4.1, and 2.5.x before 2.5.3. Attackers could leverage this vulnerability to gain unauthorized access and escalate their privileges in the system. Users are advised to update their software to mitigate potential risks associated with this flaw.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.