CVE-2021-22794: Path Traversal
Published Mar 28, 2022
·Updated
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.8.1
Event History
Mar 28, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22794.
2
What is the severity of CVE-2021-22794?
CVE-2021-22794 has a severity rating of 9.8 (Critical).
3
What is the CWE ID of CVE-2021-22794?
CVE-2021-22794 is associated with CWE-22 (Improper Limitation of a Pathname to a Restricted Directory - Path Traversal).
4
Which version of StruxureWare Data Center Expert is affected by CVE-2021-22794?
StruxureWare Data Center Expert (V7.8.1 and prior) is affected by CVE-2021-22794.
5
How can CVE-2021-22794 be exploited?
CVE-2021-22794 can be exploited through a remote code execution attack.