Lucene search

K
cvelistABBCVELIST:CVE-2021-22289
HistoryAug 11, 2022 - 2:56 p.m.

CVE-2021-22289 RCE through Project Upload from Target

2022-08-1114:56:02
CWE-20
ABB
www.cve.org
cve-2021-22289
rce
project upload
improper input validation
b&r automation studio
network attacker
code execution

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.9%

Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

CNA Affected

[
  {
    "product": "Automation Studio",
    "vendor": "B&R Industrial Automation",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "4",
        "versionType": "custom"
      }
    ]
  }
]

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.9%

Related for CVELIST:CVE-2021-22289