CVE-2021-43930
Summary
| CVE | CVE-2021-43930 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-28 15:15:00 UTC |
| Updated | 2022-05-09 13:59:00 UTC |
| Description | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Smartptt | Smartptt Scada | 1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Elcomplus SmartPPT SCADA | CISA | CONFIRM | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Michael Heinzl reported these vulnerabilities to CISA
Legacy QID Mappings
- 590902 Elcomplus SmartPTT SCADA Multiple Vulnerabilities (ICSA-22-109-04)