CVE-2021-26828: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via viewedit.shtm.
Other sources
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via viewedit.shtm.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of OpenPLC / ScadaBR if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26828?
CVE-2021-26828 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-26828?
To mitigate CVE-2021-26828, upgrade OpenPLC ScadaBR to the latest version beyond 0.9.1 for Linux and 1.12.4 for Windows.
Who is affected by CVE-2021-26828?
CVE-2021-26828 affects users of OpenPLC ScadaBR versions 0.9.1 on Linux and 1.12.4 on Windows.
What types of attacks can exploit CVE-2021-26828?
CVE-2021-26828 can be exploited by remote authenticated users to upload and execute arbitrary JSP files.
Is CVE-2021-26828 a common vulnerability in OpenPLC ScadaBR?
Yes, CVE-2021-26828 is a significant and known vulnerability affecting certain versions of OpenPLC ScadaBR.