CVE Published: 11/02/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: schneider |
Vendor: n/a |
Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) Status : PUBLISHED
CVE-2021-22803 Description
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)