CVE Database
/

CVE-2021-45420

Back to search

CVE-2021-45420

Published: Feb 14, 2022

Modified: Aug 4, 2024

PUBLISHED

Description

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced

VendorProductVersions

n/a

n/a

affected
n/a

References

http://emerson.com
x_refsource_MISC
http://dixell.com
x_refsource_MISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now