A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.
Se presenta una vulnerabilidad de Carga Sin Restricciones de Archivos con tipo Peligroso CWE-434 en EcoStruxure Building Operation WebReports versiones V1.9 - V3.1, que podría causar que un usuario remoto autenticado pueda cargar archivos arbitrarios debido a una verificación incorrecta de los archivos suministrados por el usuario y lograr una ejecución de código remoto
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:S/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | SINGLE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-434
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | webreports | * | <built-in method update of dict object at 0x7e6050bdeb80> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:webreports:*:*:*:*:*:*:*:* |