Unrestricted File Upload Vulnerability in EcoStruxure Power Build Software by Schneider Electric
CVE-2021-22698
7.8HIGH
What is CVE-2021-22698?
An unrestricted file upload vulnerability exists in the EcoStruxure Power Build - Rapsody software. This flaw allows malicious users to upload a specially crafted SSD file that can lead to a stack-based buffer overflow. If exploited, it may enable remote code execution due to the improper parsing of files within the software. Affected versions include V2.1.13 and earlier, highlighting the need for immediate attention to security practices to mitigate risks associated with this vulnerability.
Affected Version(s)
 EcoStruxure Power Build - Rapsody software V2.1.13 and prior. EcoStruxure Power Build - Rapsody software V2.1.13 and prior.