Security Advisory

CVE-2021-41578

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-10-04 17:38:23
Last updated 2024-08-04 03:15:29
Assigner mitre
State PUBLISHED

Description

mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.