Directory Traversal Vulnerability in mySCADA myDESIGNER by mySCADA
CVE-2021-41578
7.8HIGH
Summary
mySCADA myDESIGNER versions 8.20.0 and earlier are vulnerable to directory traversal attacks, which can be exploited when a user imports a specially crafted .mep file. If an attacker successfully deceives a user into executing this import, they can manipulate files in system directories where the user has write permissions, potentially leading to unauthorized code execution and significant security breaches.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved