S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-3019 Scanner

CVE-2021-3019 scanner - Directory Traversal vulnerability in ffay lanproxy

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-3019
7.5
CVSS

ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

FFay lanproxy is a software used for proxy and NAT traversal. It is mainly utilized to provide access to internal networks with no direct access to the internet. This software is favored by businesses that need to grant remote access to their employees, consultants, and partners. FFay lanproxy is designed to be user-friendly and easy to configure. It uses a web user interface to allow users to configure network settings without needing advanced technical skills.

Recently, a vulnerability was found in the FFay lanproxy software - CVE-2021-3019. This vulnerability can be exploited for a Directory Traversal attack. It allows an attacker to access restricted files, like the configuration files of the software. With this vulnerability, an attacker can potentially obtain confidential information from the client network's internal resources.

When this vulnerability is exploited, it can lead to severe consequences. For one, it can give unauthorized access to the client network's sensitive information. This includes private company data, user credentials, and financial information. Additionally, it can give an attacker control over the client network's systems, which could lead to further attacks or data breaches.

At s4e.io, we offer pro features to help individuals and businesses protect their networks. Our platform includes a vulnerability scanner that can detect potential vulnerabilities in your digital assets. With our tool, you can easily and quickly learn about any vulnerabilities and take the necessary steps to secure your network. Our team constantly works to identify new vulnerabilities like CVE-2021-3019 to help our clients stay ahead of potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that should be taken. Here are some steps that users can take to secure their network:

  • Regularly check for software updates and patches.
  • Patch the FFay lanproxy software to the latest version that includes the security fix.
  • Limit access to the software configuration files to only trusted users.
  • Use network segmentation to limit the exposure of the client network to any potential attacks.
  • Monitor the network closely for any unusual activity or traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-3019 scanner - Directory Traversal vulnerability in ffay lanproxy | S4E