PT-2021-19453 · Unknown · Open Plc Webserver

Published

2021-08-03

·

Updated

2025-02-28

·

CVE-2021-31630

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Open PLC Webserver version 3
Description Command Injection in Open PLC Webserver allows remote attackers to execute arbitrary code via the Hardware Layer Code Box component on the "/hardware" page of the application.
Recommendations As a temporary workaround, consider disabling the Hardware Layer Code Box component until a patch is available. Restrict access to the "/hardware" page to minimize the risk of exploitation. Update to a newer version that contains a fix for this issue, if available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-31630

Affected Products

Open Plc Webserver