{"api_version":"1","generated_at":"2026-07-23T12:59:58+00:00","cve":"CVE-2021-43936","urls":{"html":"https://cve.report/CVE-2021-43936","api":"https://cve.report/api/cve/CVE-2021-43936.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43936","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43936"},"summary":{"title":"CVE-2021-43936","description":"The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2021-12-06 18:15:00","updated_at":"2022-04-12 18:06:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03","name":"https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03","refsource":"MISC","tags":[],"title":"Distributed Data Systems WebHMI | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html","name":"http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html","refsource":"MISC","tags":[],"title":"WebHMI 4.0 Remote Code Execution ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43936","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43936","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Marcin Dudek of CERT.PL reported these vulnerabilities to CISA.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"43936","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"webhmi","cpe5":"webhmi","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"43936","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"webhmi","cpe5":"webhmi_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43936","qid":"590679","title":"Distributed Data Systems WebHMI Multiple Vulnerabilities (ICSA-21-336-03)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2021-43936","STATE":"PUBLIC","TITLE":"Distributed Data Systems WebHM"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"WebHMI","version":{"version_data":[{"version_affected":"<","version_name":"4.1","version_value":"4.1"}]}}]},"vendor_name":"Distributed Data Systems"}]}},"credit":[{"lang":"eng","value":"Marcin Dudek of CERT.PL reported these vulnerabilities to CISA."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution."}]},"exploit":[{"lang":"eng","value":"None"}],"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unrestricted Upload of File with Dangerous Type"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03","name":"https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html","url":"http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html"}]},"source":{"advisory":"ICSA-21-336-03","defect":["CWE-434"],"discovery":"EXTERNAL"},"work_around":[{"lang":"eng","value":"Distributed Data Systems recommends upgrading the platform software to the latest release, Version 4.1"}]},"nvd":{"publishedDate":"2021-12-06 18:15:00","lastModifiedDate":"2022-04-12 18:06:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:webhmi:webhmi_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:webhmi:webhmi:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43936","Ordinal":"221555","Title":"CVE-2021-43936","CVE":"CVE-2021-43936","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43936","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}