Vulnerability Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
CVSS Score
5.4
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scadabr | Scadabr | <= 0.9.1 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3Vendor Advisory
- https://youtu.be/Xh6LPCiLMa8ExploitThird Party Advisory
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3Vendor Advisory
- https://youtu.be/Xh6LPCiLMa8ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
- https://www.forescout.com/blog/anatomy-of-a-hacktivist-attack-russian-aligned-grThird Party Advisory
FAQ
What is CVE-2021-26829?
CVE-2021-26829 is a vulnerability with a CVSS score of 5.4 (MEDIUM). OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
How severe is CVE-2021-26829?
CVE-2021-26829 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26829?
Check the references section above for vendor advisories and patch information. Affected products include: Scadabr Scadabr, Linux Linux Kernel, Microsoft Windows.