Vulnerability Description
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Myscada | Mydesigner | <= 8.20.0 |
Related Weaknesses (CWE)
References
- https://github.com/jacob-baines/vuln_disclosure/blob/main/vuln_2021_05.txtThird Party Advisory
- https://github.com/jacob-baines/vuln_disclosure/blob/main/vuln_2021_05.txtThird Party Advisory
FAQ
What is CVE-2021-41578?
CVE-2021-41578 is a vulnerability with a CVSS score of 7.8 (HIGH). mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability t...
How severe is CVE-2021-41578?
CVE-2021-41578 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41578?
Check the references section above for vendor advisories and patch information. Affected products include: Myscada Mydesigner.