ZDI-CAN-20537: ZDI-23-1031: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability
Published Aug 4, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Triangle MicroWorks SCADA Data Gateway
Event History
Aug 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 26, 2025
Advisory Published
via ZDI·05:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20537?
ZDI-CAN-20537 is classified as a critical vulnerability that allows remote code execution.
2
How do I fix ZDI-CAN-20537?
To fix ZDI-CAN-20537, ensure that you update the Triangle MicroWorks SCADA Data Gateway to the latest version that addresses this vulnerability.
3
Who is affected by ZDI-CAN-20537?
Organizations using Triangle MicroWorks SCADA Data Gateway are affected by ZDI-CAN-20537.
4
Can ZDI-CAN-20537 be exploited without authentication?
No, ZDI-CAN-20537 requires authentication, but the existing authentication can be bypassed.
5
What type of vulnerability is ZDI-CAN-20537?
ZDI-CAN-20537 is a remote code execution vulnerability.