CVE-2021-42022: Path Traversal
A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read unexpected critical files. The affected file download function is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42022?
CVE-2021-42022 is classified as a high-severity vulnerability due to its potential to allow file path traversal attacks.
How do I fix CVE-2021-42022?
To fix CVE-2021-42022, upgrade to SIMATIC eaSie PCS 7 Skill Package version V21.00 SP3 or later.
What types of systems are affected by CVE-2021-42022?
CVE-2021-42022 affects all versions of SIMATIC eaSie PCS 7 Skill Package prior to V21.00 SP3.
What are the consequences of exploiting CVE-2021-42022?
Exploiting CVE-2021-42022 could allow an attacker to access files outside of the intended directory structure.
Is there a workaround for CVE-2021-42022 if I cannot upgrade?
There are no known workarounds for CVE-2021-42022; therefore, upgrading is the recommended remediation.