10
CVSSv2

CVE-2021-43936

Published: 06/12/2021 Updated: 12/04/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The software allows the malicious user to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webhmi webhmi_firmware

ICS Advisories

Exploits

WebHMI version 40 suffers from an authenticated remote code execution vulnerability ...

Github Repositories

CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.

CVE-2021-43936 CVE-2021-43936 is a critical vulnerability (CVSS3 100) leading to Remote Code Execution (RCE) in WebHMI Firmware This vulnerability works on versions 40 and the newest ones Tested only on 407475 Vulnerability is used by script in the following steps: Logs into the application Uploads the PHP code execution script Sends the reverse shell payload Exploit c