CVE-2021-43555

HIGH

mySCADA myDESIGNER <8.20.0 - Path Traversal

Title source: llm
STIX 2.1

Description

mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-313-04

Scores

CVSS v3 7.3
EPSS 0.3799
EPSS Percentile 98.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H

Details

CWE
CWE-22 CWE-23
Status published
Products (1)
myscada/mydesigner < 8.20.0
Published Nov 19, 2021
Tracked Since Feb 18, 2026