Known vulnerabilities in SmartPPT SCADA Server
Vendor:
Elcomplus
Software:
SmartPPT SCADA Server
Software CPE:
cpe:2.3:a:elcomplus:smartppt_scada_server:*:*:*:*:*:*:*:*
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62457 - Cross-Site Request Forgery (CSRF) CVE-2021-43937 |
CWE-352 | Low | 2.3.4 | 20.04.2022 |
SB2022042007 |
||
| #VU62456 - Exposure of sensitive information to an unauthorized actor CVE-2021-43938 |
CWE-200 | Medium | 2.3.4 | 20.04.2022 |
SB2022042007 |
||
| #VU62455 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43930 |
CWE-22 | Low | 2.3.4 | 20.04.2022 |
SB2022042006 SB2022042007 |
||
| #VU62454 - Unrestricted Upload of File with Dangerous Type CVE-2021-43934 |
CWE-434 | High | 2.3.4 | 20.04.2022 |
SB2022042006 SB2022042007 |
||
| #VU62451 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-43932 |
CWE-79 | Low | 2.3.4 | 20.04.2022 |
SB2022042006 SB2022042007 |