← All CVEs

CVE-2021-43936

critical · 10

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

10
CVSS
35.8%
EPSS (exploit prob.)
98th
EPSS percentile
2021-12-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
webhmiwebhmi_firmware< 4.1
webhmiwebhmiall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-43936