Vulnerability Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scadabr | Scadabr | <= 0.9.1 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3Broken LinkExploitVendor Advisory
- http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-UploadExploitThird Party Advisory
- https://youtu.be/k1teIStQr1AExploitThird Party Advisory
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3Broken LinkExploitVendor Advisory
- http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-UploadExploitThird Party Advisory
- https://youtu.be/k1teIStQr1AExploitThird Party Advisory
- https://github.com/SCADA-LTS/Scada-LTS/pull/2174Issue TrackingPatch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-26828?
CVE-2021-26828 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
How severe is CVE-2021-26828?
CVE-2021-26828 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26828?
Check the references section above for vendor advisories and patch information. Affected products include: Scadabr Scadabr, Linux Linux Kernel, Microsoft Windows.