Record summary

CVE-2021-43936 has a selected CVSS score of 10.0 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 9, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List4.1 to < 4.1affected
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBWebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Jeremiasz PlutaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubLongWayHomie/CVE-2021-43936Repository PoCby LongWayHomieStars: 9Not analyzed4 files

74.5 KiB

GitHub

PoC details

References

3