CVE-2021-22797
published 2022-04-13CVE-2021-22797: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed…
PriorityP354high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
26.10%
97.8th percentile
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_control_expert | < 15.1 | 15.1 |
| schneider-electric | ecostruxure_process_expert | < 2021 | 2021 |
| schneider_electric | ecostruxure_control_expert | >= unspecified < V15.0 SP1 | V15.0 SP1 |
| schneider_electric | ecostruxure_process_expert | >= unspecified < 2020 | 2020 |
| schneider_electric | scadapack_remoteconnect_for_x70 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric EcoStruxure and SCADAPack
cisa_ics·2021-09-20·CVSS 7.8
[HIGH] Schneider Electric EcoStruxure and SCADAPack
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric EcoStruxure and SCADAPack
Last RevisedSeptember 20, 2021
Alert CodeICSA-21-259-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Control Expert, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70
- Vulnerability: Path Traversal
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in code execution on the engineering workstation.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following products and versions are affected:
- EcoStru
GHSA
GHSA-qqgr-6jmg-cwgv: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be d
ghsa_unreviewed·2022-04-14
CVE-2021-22797 [HIGH] CWE-22 GHSA-qqgr-6jmg-cwgv: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be d
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-13
Published