VYPR
Unrated severityNVD Advisory· Published Oct 13, 2021· Updated Aug 3, 2024

CVE-2021-20796

CVE-2021-20796

Description

Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cybozu Remote Service 3.1.8 management screen contains a directory traversal vulnerability allowing authenticated attackers to upload arbitrary files, impacting integrity and availability.

Vulnerability

A path traversal vulnerability (CWE-22) exists in the management screen of Cybozu Remote Service 3.1.8 [1][2]. An authenticated remote attacker can exploit unspecified vectors to traverse directories and upload arbitrary files to locations outside the intended upload directory. According to [1], the CVSS v3 base score is 4.2 (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L), while [2] rates it as 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L). The affected version is exclusively 3.1.8 [1][2].

Exploitation

An attacker must have valid credentials to access the management screen (PR:L) and network access [1][2]. The attack requires no user interaction (UI:N). The exact steps are not disclosed by the vendor to prevent misuse [2]; however, the flaw allows directory traversal through the file upload functionality, enabling the attacker to specify a path that escapes the designated upload folder.

Impact

Successful exploitation allows the attacker to upload arbitrary files to arbitrary locations on the server [2]. This can lead to integrity compromise (e.g., overwriting configuration files or uploading malicious scripts) and availability degradation (e.g., replacing critical files that cause service disruption) [1][2]. There is no direct confidentiality impact [1].

Mitigation

Cybozu released version 4.0.0 on 2021-09-29 to fix this vulnerability [2]. Users should upgrade to 4.0.0 or later. No workaround or EOL status is mentioned in the references; the product remains supported [1][2]. This CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.