CVE-2021-22748: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22748?
CVE-2021-22748 is a vulnerability that allows remote code execution through a path traversal attack in Schneider-electric C-bus Toolkit.
What is the severity of CVE-2021-22748?
CVE-2021-22748 has a severity rating of 8.8, which is considered high.
Which products are affected by CVE-2021-22748?
The affected products are C-Bus Toolkit (V1.15.9 and prior) and C-Gate Server (V2.11.7 and prior) from Schneider-electric.
How does CVE-2021-22748 work?
CVE-2021-22748 exploits a path traversal vulnerability to execute remote code by manipulating file saving operations.
What is the fix for CVE-2021-22748?
To fix CVE-2021-22748, users should update to the latest versions of C-Bus Toolkit (V1.16.0 or later) and C-Gate Server (V2.11.8 or later) provided by Schneider-electric.