CVE-2021-22794
published 2022-04-13CVE-2021-22794: A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.08%
79.4th percentile
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | struxureware_data_center_expert | <= 7.8.1 | — |
| schneider_electric | struxureware_data_center_expert | >= unspecified < V7.8.1 | V7.8.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-22794 is a Path Traversal (CWE-22) vulnerability in Schneider Electric StruxureWare Data Center Expert versions 7.8.1 and prior, exploitable remotely with low attack complexity and high privileges, potentially leading to remote code execution. ↗
- →No known public exploits specifically target this vulnerability as of the advisory date (September 14, 2021); monitor for anomalous path traversal patterns in HTTP requests targeting StruxureWare Data Center Expert management interfaces. ↗
- ·CVSS v3 base score is 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) — network-exploitable, low complexity, but requires high privileges; scope is changed indicating impact beyond the vulnerable component. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Struxureware Data Center Expert
cisa_ics·2021-09-14·CVSS 9.1
[CRITICAL] Schneider Electric Struxureware Data Center Expert
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Struxureware Data Center Expert
Last RevisedSeptember 14, 2021
Alert CodeICSA-21-257-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: Struxureware Data Center Expert
- Vulnerabilities: OS Command Injection, Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Struxureware Data Center Expert, a monitoring software, are affe
GHSA
GHSA-c53q-88xr-x99v: A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution
ghsa_unreviewed·2022-04-14
CVE-2021-22794 [CRITICAL] CWE-22 GHSA-c53q-88xr-x99v: A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-13
Published