CVE-2021-32955: Malicious File Upload
Published Aug 30, 2021
·Updated
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.
Affected Software
2 affected componentsFixes available
Delta Electronics DIAEnergie<1.9
1.9
Deltaww Diaenergie<=1.7.5
Event History
Aug 30, 2021
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionWeakness
Aug 3, 2024
Data Sourced
via ICS·11:42 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-32955?
CVE-2021-32955 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2021-32955?
To fix CVE-2021-32955, upgrade to DIAEnergie version 1.9 or later.
3
What type of vulnerability is CVE-2021-32955?
CVE-2021-32955 is an unrestricted file upload vulnerability.
4
Which versions of DIAEnergie are affected by CVE-2021-32955?
DIAEnergie versions 1.7.5 and earlier are affected by CVE-2021-32955.
5
Can CVE-2021-32955 lead to data breaches?
Yes, CVE-2021-32955 can potentially lead to data breaches due to its ability to execute arbitrary code.