← back
CVE-2021-43930mediumCWE-22

Elcomplus SmartPtt Path Traversal

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.9epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
Elcomplus · SmartPTT