Vulnerability Details CVE-2021-29101
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 81.2%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 5.0
Products affected by CVE-2021-29101
-
cpe:2.3:a:esri:arcgis_geoevent_server:-
-
cpe:2.3:a:esri:arcgis_geoevent_server:10.8.1