LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-40870: Aviatrix Controller Unrestricted Upload of File

RBRecent Breaches Vulnerability Intelligence·Jan 18, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-40870 to its Known Exploited Vulnerabilities catalog on Jan 18, 2022, with a federal patch deadline of Feb 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

CVE-2021-40870 is an unrestricted file-upload weakness in the Aviatrix Controller that lets an unauthenticated attacker place a dangerous file type and, through directory traversal, achieve arbitrary code execution on the controller. Controllers of this class often sit at the center of cloud networking and hold privileged access to infrastructure, so a successful exploit can give an attacker a strong foothold for further movement or configuration abuse. Specifics such as exact affected builds must be confirmed against the vendor advisory.

How it works

The issue combines unrestricted upload of a file with a dangerous type (related to CWE-96 style code-injection concerns) with directory traversal (CWE-25). In plain terms, the controller accepts an uploaded file without adequately restricting type or destination path. An unauthenticated user can supply a path that escapes the intended upload directory and lands the file where the application or underlying system will treat it as executable or interpretable code. Once that file is in place and reachable, the attacker can trigger execution and run arbitrary commands in the context of the controller process. Public detail beyond this class of behavior is limited; do not assume particular endpoints, payloads, or post-exploitation steps without checking the vendor advisory and your own telemetry.

Am I affected? How to find it in your systems

Aviatrix Controller is typically deployed as a management appliance or instance that orchestrates cloud network connectivity (transit, gateways, and related policy). Inventory any hosts, VMs, or containers running Aviatrix Controller software, including non-production and lab instances that may still be reachable.

How to remediate

Patch first. Apply the updates provided by the vendor exactly as described in their advisory and in line with CISA’s required action to apply updates per vendor instructions. After patching, verify the controller version and restart or reload services if the advisory requires it. Then harden the deployment for this weakness class:

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited controller vulnerabilities can lead to full compromise of the management plane and subsequent access to connected cloud resources or credentials. Known ransomware use is not documented for this CVE, but that does not rule out other malicious use. If you suspect exploitation, isolate the controller, preserve logs and disk images, rotate credentials and keys that the controller could access, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior dumps while you continue containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAviatrix · Aviatrix Controller
WeaknessCWE-25
Added to CISA KEVJan 18, 2022
Federal patch deadlineFeb 1, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities