The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03 | Patch Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2021-12-06 18:15
Updated : 2022-04-12 18:06
NVD link : CVE-2021-43936
Mitre link : CVE-2021-43936
CVE.ORG link : CVE-2021-43936
JSON object : View
Products Affected
webhmi
- webhmi_firmware
- webhmi
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type