Vulnerability record · CVE-2021-40870 · published 13 September 2021
CVE-2021-40870: Aviatrix Controller unauthenticated file upload leads to RCE
Aviatrix · Controller
Aviatrix Controller 6.x before 6.5-1804.1922 allows unrestricted upload of a dangerous file type, and directory traversal lets an unauthenticated attacker place and execute arbitrary code. The flaw is remotely reachable with no credentials or user interaction, making it a direct path to full compromise of the controller.
Description
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, KEV listing, and near-maximum EPSS probability makes this an urgent patch.
What it is
Aviatrix Controller 6.x before 6.5-1804.1922 allows unrestricted upload of a dangerous file type, and directory traversal lets an unauthenticated attacker place and execute arbitrary code. The flaw is remotely reachable with no credentials or user interaction, making it a direct path to full compromise of the controller.
Impact
An attacker gains remote code execution on the Aviatrix Controller, which can lead to full control of the controller and the network infrastructure it manages.
Attack surface
Reachable over the network via the controller's web interface; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt the upload and traversal.
Exploitation
Listed in CISA KEV since 2022-01-18 with a required action to apply vendor updates, and EPSS 30-day probability is 0.93 (99.8th percentile). Public exploit references are tagged Exploit, indicating working exploit code is available.
What to do
- Upgrade Aviatrix Controller to 6.5-1804.1922 or later per the vendor release notes.
- If immediate patching is not possible, restrict network access to the controller management interface to trusted hosts only.
- Monitor and block directory traversal patterns and unexpected file uploads at the perimeter or WAF.
- Rotate credentials and review controller logs for signs of compromise after exposure.
- Verify no unauthorized files or processes were placed on the controller before remediation.
Detection
- Inspect controller and web server logs for upload requests containing traversal sequences such as ../ or encoded variants.
- Alert on file creation in web-accessible or executable directories outside expected deployment paths.
- Monitor for unexpected outbound connections or new processes spawned by the controller service.
- Hunt for known exploit request patterns against the controller endpoint using the public advisory indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40870 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Aviatrix Controller Unrestricted Upload of File". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164461/Aviatrix-Controller-6.x-Path-Traversal-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://docs.aviatrix.com/HowTos/UCC_Release_Notes.html#security-note-9-11-2021 | Release NotesVendor Advisory |
| https://wearetradecraft.com/advisories/tc-2021-0002/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/164461/Aviatrix-Controller-6.x-Path-Traversal-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://docs.aviatrix.com/HowTos/UCC_Release_Notes.html#security-note-9-11-2021 | Release NotesVendor Advisory |
| https://wearetradecraft.com/advisories/tc-2021-0002/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40870 | US Government Resource |
Track CVE-2021-40870 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40870), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.