PT-2021-6931 · Elcomplus · Elcomplus Smartptt Scada Server
Michael Heinzl
·
Published
2021-04-21
·
Updated
2022-05-11
·
CVE-2021-43937
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elcomplus SmartPTT SCADA Server (affected versions not specified)
Description
The issue is related to insufficient verification of the source of HTTP requests. This can allow a remote attacker to perform a CSRF attack using a specially crafted web page. The problem arises because the Elcomplus SmartPTT SCADA Server web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elcomplus Smartptt Scada Server