CVE report

CVE-2021-42013CRITICALKEV

Apache CGI Path Traversal / Self-Rep Payload

Events 90d

1,786

Distinct IPs

768

Severity

CRITICAL

CISA KEV

Actively exploited

Detection signature

An event counts toward CVE-2021-42013 when its URL path contains any of these (case-insensitive). This is what our matching is based on.

  • · apache.selfrep
  • · /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd
  • · /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd
  • · /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh

Pre-disclosure activity

all early actors →

Analysing probe history around the publication date…

Recent probe volume (last 7 days)

peak: 42 events/day
04-2805-1105-2406-0606-1907-0207-1507-27
eventsdistinct IPs

Downloads & integrations

Top sources probing for CVE-2021-42013

Top networks the attempts come from

Fingerprints of the clients exploiting this

The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.

Sample request paths observed

  • /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd
  • /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd
  • /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh