First published: Wed Feb 24 2021(Updated: )
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec SV-CPT-MC310 Firmware | <6.5 | |
Contec SV-CPT-MC310 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20659 is categorized as a medium severity vulnerability due to the potential for authenticated attackers to execute arbitrary code.
To mitigate CVE-2021-20659, upgrade the SolarView Compact SV-CPT-MC310 firmware to version 6.5 or later.
In CVE-2021-20659, an attacker can upload arbitrary files, including PHP scripts, that can be executed.
Yes, exploiting CVE-2021-20659 requires authentication to the SolarView Compact SV-CPT-MC310.
The consequences of CVE-2021-20659 include unauthorized remote code execution, which could compromise the integrity of the system.