PT-2021-23343 · Myscada · Myscada Mydesigner

Published

2021-10-04

·

Updated

2021-10-12

·

CVE-2021-41578

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mySCADA myDESIGNER versions 8.20.0 and below
Description The issue allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
Recommendations For mySCADA myDESIGNER versions 8.20.0 and below, consider restricting the import of project files or validating the files before import to minimize the risk of exploitation. As a temporary workaround, avoid importing mep files from untrusted sources until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41578

Affected Products

Myscada Mydesigner