CVE-2021-41578: Path Traversal
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41578?
CVE-2021-41578 is considered a critical vulnerability due to its potential for arbitrary file writing and directory traversal attacks.
How do I fix CVE-2021-41578?
To fix CVE-2021-41578, upgrade mySCADA myDESIGNER to version 8.21.0 or later.
What systems are affected by CVE-2021-41578?
CVE-2021-41578 affects all versions of mySCADA myDESIGNER up to and including 8.20.0.
What can an attacker do with CVE-2021-41578?
An attacker can exploit CVE-2021-41578 to write arbitrary files to the operating system locations where the user has permissions.
What is the nature of CVE-2021-41578 attack vector?
CVE-2021-41578 enables directory traversal attacks when importing project files, leading to serious security risks.