PT-2021-6931 · Elcomplus · Elcomplus Smartptt Scada Server

Michael Heinzl

·

Published

2021-04-21

·

Updated

2022-05-11

·

CVE-2021-43937

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elcomplus SmartPTT SCADA Server (affected versions not specified)
Description The issue is related to insufficient verification of the source of HTTP requests. This can allow a remote attacker to perform a CSRF attack using a specially crafted web page. The problem arises because the Elcomplus SmartPTT SCADA Server web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02691
CVE-2021-43937

Affected Products

Elcomplus Smartptt Scada Server