SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27198

Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI.

CRITICAL 9.8EPSS 13.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
13.62% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
visualware/myconnection server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.