CVE-2021-41578

mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:myscada:mydesigner:*:*:*:*:*:*:*:*

Information

Published : 2021-10-04 11:15

Updated : 2021-10-12 14:41


NVD link : CVE-2021-41578

Mitre link : CVE-2021-41578


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

myscada

  • mydesigner