Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
Metrics
Affected Vendors & Products
Fixes
Solution
Elcomplus has released an update to fix these vulnerabilities and recommends users upgrade to Version 2.3.4 or later. For more information, please contact Elcomplus support.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:27:52.498Z
Reserved: 2021-11-16T00:00:00.000Z
Link: CVE-2021-43930

No data.

Status : Modified
Published: 2022-04-28T15:15:08.913
Modified: 2024-11-21T06:30:01.260
Link: CVE-2021-43930

No data.

No data.