{"api_version":"1","generated_at":"2026-07-23T14:32:11+00:00","cve":"CVE-2021-43930","urls":{"html":"https://cve.report/CVE-2021-43930","api":"https://cve.report/api/cve/CVE-2021-43930.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43930","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43930"},"summary":{"title":"CVE-2021-43930","description":"Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2022-04-28 15:15:00","updated_at":"2022-05-09 13:59:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04","name":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04","refsource":"CONFIRM","tags":[],"title":"Elcomplus SmartPPT SCADA | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43930","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43930","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Michael Heinzl reported these vulnerabilities to CISA","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"43930","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"smartptt","cpe5":"smartptt_scada","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43930","qid":"590902","title":"Elcomplus SmartPTT SCADA Multiple Vulnerabilities (ICSA-22-109-04)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2021-43930","STATE":"PUBLIC","TITLE":"Elcomplus SmartPtt Path Traversal"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SmartPTT","version":{"version_data":[{"version_affected":"=","version_value":"1.1"}]}}]},"vendor_name":"Elcomplus"}]}},"credit":[{"lang":"eng","value":"Michael Heinzl reported these vulnerabilities to CISA"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}]}]},"references":{"reference_data":[{"name":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04","refsource":"CONFIRM","url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04"}]},"solution":[{"lang":"eng","value":"Elcomplus has released an update to fix these vulnerabilities and recommends users upgrade to Version 2.3.4 or later.\n\nFor more information, please contact Elcomplus support."}],"source":{"advisory":"ICSA-22-109-04","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-04-28 15:15:00","lastModifiedDate":"2022-05-09 13:59:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:smartptt:smartptt_scada:1.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43930","Ordinal":"221549","Title":"CVE-2021-43930","CVE":"CVE-2021-43930","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43930","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}