Path traversal in Schneider Electric products - CVE-2021-22796
Published: September 17, 2021
Vulnerability identifier: #VU56670
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22796
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted project file and execute arbitrary code on the target system.
Affected software
EcoStruxure Control Expert
EcoStruxure Process Expert
SCADAPack RemoteConnect for x70
EcoStruxure Process Expert
SCADAPack RemoteConnect for x70
How to mitigate CVE-2021-22796
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.