#VU57971 Modification of assumed-immutable data in DAQFactory - CVE-2021-42701
Published: November 8, 2021
DAQFactory
AzeoTech
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to application does not perform validation of the attacker-controlled data, assuming that data is valid and safe. A remote authenticated attacker can trick a victim to open a specially crafted project file, perform a man-in-the-middle (MiTM) attack to obtain credentials and take over the user’s cloud account.