Vulnerability Details CVE-2021-32949
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-32949
-
cpe:2.3:a:auvesy-mdt:autosave:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:5.00