9.3
CVE-2021-22797
- EPSS 0.45%
- Veröffentlicht 13.04.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:50:41
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Ecostruxure Control Expert Version < 15.1
Schneider-electric ≫ Ecostruxure Process Expert Version < 2021
Schneider-electric ≫ Remoteconnect Version-
Schneider-electric ≫ Scadapack 470 Version-
Schneider-electric ≫ Scadapack 474 Version-
Schneider-electric ≫ Scadapack 570 Version-
Schneider-electric ≫ Scadapack 574 Version-
Schneider-electric ≫ Scadapack 575 Version-
Schneider-electric ≫ Scadapack 474 Version-
Schneider-electric ≫ Scadapack 570 Version-
Schneider-electric ≫ Scadapack 574 Version-
Schneider-electric ≫ Scadapack 575 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.627 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
cybersecurity@se.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.