← Back

CVE-2021-41583

nvd nist
Published: Sep 24, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access.

Affected (1)

1 product
Vpn User Portal
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
From 2.3.2 to 2.3.14
Running on/withPlatform Versions
Debian
Debian Linux
Version 10.0
Debian
Debian Linux
Version 11.0
Fedoraproject
Fedora
All versions

References (3)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: nvd@nist.gov
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.