CVE-2021-32498: Path Traversal
Published Dec 17, 2021
·Updated
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead of the emulator
Affected Software
1 affected component
SICK Sopas Engineering Tool<4.8.0
Remediation
Patch Available
Event History
Dec 17, 2021
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32498?
CVE-2021-32498 has been assigned a medium severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2021-32498?
To fix CVE-2021-32498, upgrade to SICK SOPAS ET version 4.8.0 or later.
3
What systems are affected by CVE-2021-32498?
CVE-2021-32498 affects SICK SOPAS ET versions before 4.8.0.
4
What kind of attack does CVE-2021-32498 enable?
CVE-2021-32498 enables attackers to manipulate pathnames and execute arbitrary executables on the host system.
5
What does the exploit for CVE-2021-32498 involve?
The exploit for CVE-2021-32498 involves using path traversal techniques to launch unauthorized executables.