packetstormsecurity.com
http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html CVE-2021-43936
CRITICAL
Distributed Data Systems WebHM
Record summary
CVE-2021-43936 has a selected CVSS score of 10.0 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 4.1 to < 4.1 | affected | |
webhmi_firmwareBrowse webhmi / webhmi_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBWebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Jeremiasz PlutaNot analyzed1 file
Repository PoCs
GitHubLongWayHomie/CVE-2021-43936Repository PoCby LongWayHomieStars: 9Not analyzed4 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-43936 us-cert.cisa.gov
https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03