CVE-2021-45967
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 21%
from disclosure to weapon
Published on NVDMar 18
VulnCheck+675d
exploitation probability
21%top 3% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
Affected products
n/a · n/a