CVE-2021-22717: Schneider Electric C-Bus Toolkit ACCESS SAVE Directory Traversal Remote Code Execution Vulnerability
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric C-Bus Toolkit. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of commands sent to the C-Gate 2 Service. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Schneider Electric C-Bus Toolkit vulnerability?
The vulnerability ID for this Schneider Electric C-Bus Toolkit vulnerability is CVE-2021-22717.
What is the severity of CVE-2021-22717?
The severity of CVE-2021-22717 is high with a severity value of 8.8.
How can remote attackers exploit CVE-2021-22717?
Remote attackers can exploit CVE-2021-22717 by executing arbitrary code on affected installations of Schneider Electric C-Bus Toolkit, bypassing the existing authentication mechanism.
Which version of Schneider Electric C-Bus Toolkit is affected by CVE-2021-22717?
Schneider Electric C-Bus Toolkit up to version 1.15.7 is affected by CVE-2021-22717.
Is there a fix available for CVE-2021-22717?
Yes, Schneider Electric has released a fix for CVE-2021-22717. Please refer to the official Schneider Electric security advisory for more information.