Lucene search

K
osvGoogleOSV:CVE-2021-31800
HistoryMay 05, 2021 - 11:15 a.m.

CVE-2021-31800

2021-05-0511:15:00
Google
osv.dev
5
path traversal
smbserver.py
arbitrary code execution
impacket
file listing
file writing
cve-2021-31800
security vulnerability
ssh authorized key

AI Score

7.6

Confidence

Low

EPSS

0.014

Percentile

86.5%

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via …/ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

References