Lucene search

K
cveTwcertCVE-2021-44164
HistoryDec 20, 2021 - 3:15 a.m.

CVE-2021-44164

2021-12-2003:15:06
CWE-434
twcert
web.nvd.nist.gov
25
cve-2021-44164
chain sea
ai chatbot
file upload
remote attacker
bypass
file type validation
malicious script
execute
arbitrary code
authentication
system control
service termination

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.059

Percentile

93.5%

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

Affected configurations

Nvd
Node
chinaseaqb_smart_service_robotMatch-
VendorProductVersionCPE
chinaseaqb_smart_service_robot-cpe:2.3:a:chinasea:qb_smart_service_robot:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ai chatbot system",
    "vendor": "Chain Sea Information Integration Co., Ltd",
    "versions": [
      {
        "status": "unknown",
        "version": "0"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.059

Percentile

93.5%

Related for CVE-2021-44164