The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03 | Patch Third Party Advisory US Government Resource |
http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-12-06 10:15
Updated : 2022-04-12 11:06
NVD link : CVE-2021-43936
Mitre link : CVE-2021-43936
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
webhmi
- webhmi_firmware
- webhmi