SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34820

Web Path Directory Traversal in the Novus HTTP Server.

HIGH 7.5EPSS 4.00%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data. The issue was discovered in the NMS (Novus Management System) software through 1.51.2

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
4.00% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
aat/novus management system
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.