S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-3223 Scanner

Detects 'Directory Traversal' vulnerability in Node-RED-Dashboard affects v. before 2.26.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-3223
7.5
CVSS

Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Node-RED-Dashboard is a web-based application that allows users to visualize, interact, and control their Internet of Things (IoT) devices. Specifically, it is used to create customizable dashboards that display real-time data and status updates. With Node-RED-Dashboard, users can build custom node-red flows, easily connect to different IoT devices, and create fully functional interfaces to monitor and manage their connected devices.

Recently, a vulnerability was detected in Node-RED-Dashboard, which has been assigned the code CVE-2021-3223. This specific vulnerability pertains to directory traversal, wherein an attacker could potentially read files by exploiting a flaw in the application's file system. In essence, this vulnerability allows an attacker to access prohibitive areas of the file system, gaining unauthorized access through an over-permissive configuration.

If this vulnerability were to be successfully exploited, it could lead to a number of dangerous consequences. For instance, sensitive information stored in the impacted files may be exposed, compromised, or exfiltrated. Additionally, this exploit may serve as a pivot point for further exploitations, leading to the complete compromise of the system.

In conclusion, Node-RED-Dashboard is a powerful tool for IoT device management, but like any software solution, it can be subject to vulnerabilities. CVE-2021-3223 serves as a reminder of the importance of staying vigilant when it comes to web application security. s4e.io offers a pro feature that can simplify this process by providing ongoing vulnerability assessments and actionable remediations for digital assets. By subscribing to this feature, users can be confident that their web applications are free from vulnerabilities and can be safely used to manage and monitor connected devices.

 

REFERENCES

Solution Advice

Fortunately, there are some precautions that users can take to protect against this vulnerability. Here are some recommendations: 

  • Update to the latest version of Node-RED Dashboard, which includes a patch for CVE-2021-3223.
  • Regularly perform vulnerability scans and penetration testing on web applications such as Node-RED Dashboard to identify vulnerabilities and remediate them.
  • Implement access controls and permissions to limit the data that can be read by users, especially when it comes to sensitive information.
  • Use a web application firewall (WAF) to monitor and block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-3223 scanner - Directory Traversal vulnerability in Node-RED-Dashboard | S4E