CVE-2021-47770: OpenPLC 3 - Remote Code Execution
OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network connection to a specified IP and port, enabling remote command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47770?
CVE-2021-47770 is classified as a critical vulnerability due to its potential for authenticated remote code execution.
How do I fix CVE-2021-47770?
To mitigate CVE-2021-47770, ensure that you update OpenPLC to the latest version that addresses this vulnerability.
Who is affected by CVE-2021-47770?
CVE-2021-47770 affects users of OpenPLC v3 who have valid credentials and access to the hardware configuration interface.
What kind of attack can exploit CVE-2021-47770?
CVE-2021-47770 can be exploited through the injection of malicious code, allowing attackers to perform remote code execution.
Can CVE-2021-47770 be remotely exploited?
Yes, CVE-2021-47770 allows remote exploitation by authenticated users with valid credentials.