CVE-2021-22289: RCE through Project Upload from Target
Published Aug 11, 2022
·Updated
Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.
Affected Software
1 affected component
Br-automation Studio>=4.0
Event History
Aug 11, 2022
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-22289.
2
What is the severity level of CVE-2021-22289?
The severity level of CVE-2021-22289 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2021-22289?
The affected software for CVE-2021-22289 is B&R Automation Studio version >=4.0.
4
What is the CWE ID for CVE-2021-22289?
The CWE ID for CVE-2021-22289 is CWE-20.
5
Are there any references for CVE-2021-22289?
Yes, you can find a reference for CVE-2021-22289 at https://www.br-automation.com/downloads_br_productcatalogue/assets/1640529306294-en-original-1.0.pdf.