Description
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9833 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed. |
References
History
No history.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-03T18:51:07.283Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22698
No data.
Status : Modified
Published: 2021-01-26T18:16:18.927
Modified: 2024-11-21T05:50:29.123
Link: CVE-2021-22698
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD