CVE-2021-30357
medium · 5.3SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.
5.3
CVSS
22.8%
EPSS (exploit prob.)
98th
EPSS percentile
2021-06-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-209
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| checkpoint | ssl_network_extender | r80.10 |
| checkpoint | ssl_network_extender | r80.20 |
| checkpoint | ssl_network_extender | r80.30 |
| checkpoint | ssl_network_extender | r80.40 |
| checkpoint | ssl_network_extender | r81 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-30357