ID

VAR-202105-1704


TITLE

Anhui Xeda Software Technology Co., Ltd. Xeda OA has an arbitrary file download vulnerability

Trust: 0.6

sources: CNVD: CNVD-2021-29066

DESCRIPTION

Anhui Xieda Software Technology Co., Ltd. was established on May 16, 2008. The legal representative Ru Caifeng, the company's business scope includes: software and mobile Internet application technology development in the field of information technology, technical consulting, technical services, cloud platform and application technology development, cloud video surveillance platform development and technical maintenance, and Internet of Things applications Development and integration, communication system development and integration, computer information system integration, computer automation system integration, security monitoring system integration, computer software and hardware and auxiliary equipment, electronic equipment, video monitoring equipment, Internet of Things equipment, communication equipment, electronic product sales, network engineering , Communication Engineering, etc. Anhui Xieda Software Technology Co., Ltd. Xieda OA has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-29066

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-29066

AFFECTED PRODUCTS

vendor:anhui xiedamodel:oascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-29066

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-29066
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-29066
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-29066

EXTERNAL IDS

db:CNVDid:CNVD-2021-29066

Trust: 0.6

sources: CNVD: CNVD-2021-29066

SOURCES

db:CNVDid:CNVD-2021-29066

LAST UPDATE DATE

2022-05-04T09:37:46.706000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-29066date:2021-04-17T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-29066date:2021-05-19T00:00:00