Path Manipulation Vulnerability in LibreNMS by LibreNMS
CVE-2021-44278

9.8CRITICAL

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
3 December 2021

What is CVE-2021-44278?

LibreNMS version 21.11.0 is susceptible to a path manipulation vulnerability which can potentially enable attackers to manipulate file paths, disrupting normal application operations or accessing unauthorized data. This vulnerability exists in the file 'includes/html/pages/device/showconfig.inc.php', where input may not be properly validated, allowing for potential exploit scenarios. It is crucial for users to assess the impact of this vulnerability and take appropriate steps to mitigate risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.