CVE-2021-43936
Summary
| CVE | CVE-2021-43936 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-06 18:15:00 UTC |
| Updated | 2022-04-12 18:06:00 UTC |
| Description | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Webhmi | Webhmi | - | All | All | All |
| Operating System | Webhmi | Webhmi Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Distributed Data Systems WebHMI | CISA | MISC | us-cert.cisa.gov | |
| WebHMI 4.0 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Marcin Dudek of CERT.PL reported these vulnerabilities to CISA.
Legacy QID Mappings
- 590679 Distributed Data Systems WebHMI Multiple Vulnerabilities (ICSA-21-336-03)