CVE-2021-29101 HIGH

CVE-2021-29101: ArcGIS GeoEvent Server has a Directory Traversal security vulnerability.

Vendor Esri
Product ArcGIS GeoEvent Server
Weakness CWE-23
Published May 5, 2021
Last update April 10, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

Key dates

02Disclosure timeline

May 5, 2021 CVE published
April 10, 2025 Record updated