PT-2021-4724 · Unknown · Xarrow Scada

Michael Heinzl

+1

·

Published

2021-08-17

·

Updated

2022-05-25

·

CVE-2021-33025

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xArrow SCADA versions 7.2 and prior
Description The issue is related to the possibility of launching unvalidated registry keys with application-level privileges, which could allow an attacker to bypass existing security restrictions and elevate their privileges.
Recommendations For xArrow SCADA versions 7.2 and prior, consider restricting the use of unvalidated registry keys to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05430
CVE-2021-33025

Affected Products

Xarrow Scada