Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-04-28T14:53:29
Updated: 2024-08-04T04:10:16.986Z
Reserved: 2021-11-16T00:00:00
Link: CVE-2021-43930
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-04-28T15:15:08.913
Modified: 2024-11-21T06:30:01.260
Link: CVE-2021-43930
Redhat
No data.