CVE-2021-26828
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
OpenPLC ScadaBR allows logged-in users to upload and run malicious JSP files on the server. This lets attackers take control of the system after gaining access to a user account.
Arbitrary file upload vulnerability in view_edit.shtm endpoint affecting OpenPLC ScadaBR (Linux ≤0.9.1, Windows ≤1.12.4). Authenticated users can upload JSP files that execute with server privileges, leading to remote code execution. Attack requires valid credentials but no additional exploitation steps.
The full analysis of this CVE is available in Portuguese →