PT-2021-7784 · Igss+1 · Igss+1
Published
2021-10-12
·
Updated
2022-02-18
·
CVE-2021-22803
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Interactive Graphical SCADA System (IGSS) versions prior to 15.0.0.21243
Interactive Graphical SCADA System Data Collector (dc.exe) versions 15.0.0.21243 and prior
Description
The issue is related to an unrestricted upload of files with dangerous types, which could allow a remote attacker to execute arbitrary code. This can be achieved by sending constructed messages on the network, allowing the attacker to write arbitrary files to folders in the context of the DC module.
Recommendations
For versions prior to 15.0.0.21243, update to a version that contains a fix for this issue.
For Interactive Graphical SCADA System Data Collector (dc.exe) versions 15.0.0.21243 and prior, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the DC module to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Igss
Dc.Exe