First published: Fri Feb 11 2022(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric C-bus Toolkit | <=1.15.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22748 is a vulnerability that allows remote code execution through a path traversal attack in Schneider-electric C-bus Toolkit.
CVE-2021-22748 has a severity rating of 8.8, which is considered high.
The affected products are C-Bus Toolkit (V1.15.9 and prior) and C-Gate Server (V2.11.7 and prior) from Schneider-electric.
CVE-2021-22748 exploits a path traversal vulnerability to execute remote code by manipulating file saving operations.
To fix CVE-2021-22748, users should update to the latest versions of C-Bus Toolkit (V1.16.0 or later) and C-Gate Server (V2.11.8 or later) provided by Schneider-electric.