CISA Known Exploited Vulnerability

CVE-2021-26828

OpenPLC · ScadaBR

OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

Date added
BOD 22-01 due date
CWE CWE-434
Ransomware Unknown

CISA description

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes & references