← Back to browse · API

CVE-2021-22797

Severity
HIGH
CVSS
7.8
EPSS
0.261
Risk score
40.34
CISA KEV
No
PoC
No
Published
2022-03-28
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-9932, GHSA-QQGR-6JMG-CWGV
Products
Schneider Electric:EcoStruxure Control Expert unspecified <V15.0 SP1, Schneider Electric:EcoStruxure Process Expert unspecified <2020, Schneider Electric:SCADAPack RemoteConnect for x70 All versions
Sources
euvd EUVD-2021-9932

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)

References