PT-2021-6951 · Myscada · Myscada Mydesigner

Michael Heinzl

·

Published

2021-11-19

·

Updated

2022-07-25

·

CVE-2021-43555

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mySCADA myDESIGNER versions 8.20.0 and prior
Description The issue is related to errors in processing relative paths to directories when importing a project file. This may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution. The vulnerability is associated with the improper validation of the contents of an imported project file.
Recommendations For mySCADA myDESIGNER versions 8.20.0 and prior, consider restricting the import of project files from untrusted sources until a patch is available. As a temporary workaround, validate the contents of imported project files manually to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02722
CVE-2021-43555

Affected Products

Myscada Mydesigner