Vulnerability Details CVE-2021-35975
Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.1%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2021-35975
-
cpe:2.3:a:systematica:financial_calculator:1.3.05
-
cpe:2.3:a:systematica:fix_adapter:2.4.0.25
-
cpe:2.3:a:systematica:http_adapter:1.8.0.15
-
cpe:2.3:a:systematica:mssql_messagebus_proxy:1.1.06
-
cpe:2.3:a:systematica:radius:3.9.256.777
-
cpe:2.3:a:systematica:smtp_adapter:2.0.1.101