PT-2021-7784 · Igss+1 · Igss+1

Published

2021-10-12

·

Updated

2022-02-18

·

CVE-2021-22803

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Interactive Graphical SCADA System (IGSS) versions prior to 15.0.0.21243 Interactive Graphical SCADA System Data Collector (dc.exe) versions 15.0.0.21243 and prior
Description The issue is related to an unrestricted upload of files with dangerous types, which could allow a remote attacker to execute arbitrary code. This can be achieved by sending constructed messages on the network, allowing the attacker to write arbitrary files to folders in the context of the DC module.
Recommendations For versions prior to 15.0.0.21243, update to a version that contains a fix for this issue. For Interactive Graphical SCADA System Data Collector (dc.exe) versions 15.0.0.21243 and prior, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the DC module to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02899
CVE-2021-22803
ZDI-21-1151

Affected Products

Igss
Dc.Exe