Directory Traversal Vulnerability in mySCADA myDESIGNER by mySCADA
CVE-2021-41578

7.8HIGH

Key Information:

Vendor
Myscada
Vendor
CVE Published:
4 October 2021

Summary

mySCADA myDESIGNER versions 8.20.0 and earlier are vulnerable to directory traversal attacks, which can be exploited when a user imports a specially crafted .mep file. If an attacker successfully deceives a user into executing this import, they can manipulate files in system directories where the user has write permissions, potentially leading to unauthorized code execution and significant security breaches.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.