CVE-2021-22803
11.02.2022, 18:15
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | interactive_graphical_scada_system_data_collector | 𝑥 ≤ 15.0.0.21243 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration