356
VMScore

CVE-2021-43930

Published: 28/04/2022 Updated: 09/05/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smartptt smartptt scada 1.1

ICS Advisories

Elcomplus SmartPPT SCADA Server
Critical Infrastructure Sectors: Communications
Elcomplus SmartPPT SCADA
Critical Infrastructure Sectors: Communications