CVE-2021-41583
Estado: ModificadaMedia (6.5)—
vpn-user-portal (también se conoce como eduVPN o Let's Connect!) versiones anteriores a 2.3.14, empaquetado para Debian 10, Debian 11 y Fedora, permite a usuarios remotos autenticados conseguir acceso al sistema de archivos del Sistema Operativo, debido a una interacción de los códigos QR con un exec que utiliza la opción -r. Esto puede ser aprovechado para conseguir acceso adicional a la VPN.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.88%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-41583",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-09-24T03:15:06.620",
"references": [
{
"url": "https://list.surfnet.nl/pipermail/eduvpn-deploy/2021-September/000352.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/eduvpn/vpn-user-portal/releases",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "nvd@nist.gov"
},
{
"url": "https://list.surfnet.nl/pipermail/eduvpn-deploy/2021-September/000352.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access."
},
{
"lang": "es",
"value": "vpn-user-portal (también se conoce como eduVPN o Let's Connect!) versiones anteriores a 2.3.14, empaquetado para Debian 10, Debian 11 y Fedora, permite a usuarios remotos autenticados conseguir acceso al sistema de archivos del Sistema Operativo, debido a una interacción de los códigos QR con un exec que utiliza la opción -r. Esto puede ser aprovechado para conseguir acceso adicional a la VPN."
}
],
"lastModified": "2026-06-17T04:08:41.090",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eduvpn:vpn-user-portal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1CE96AC-501B-4C60-A2DE-A1200463A50B",
"versionEndExcluding": "2.3.14",
"versionStartIncluding": "2.3.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
},
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D3FEADDA-2AEE-4F65-9401-971B585664A8"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}