Directory Traversal Vulnerability in mySCADA myDESIGNER by mySCADA
CVE-2021-41578

7.8HIGH

Key Information:

Vendor

Myscada

Vendor
CVE Published:
4 October 2021

What is CVE-2021-41578?

mySCADA myDESIGNER versions 8.20.0 and earlier are vulnerable to directory traversal attacks, which can be exploited when a user imports a specially crafted .mep file. If an attacker successfully deceives a user into executing this import, they can manipulate files in system directories where the user has write permissions, potentially leading to unauthorized code execution and significant security breaches.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.