EXPOSURES › CVE-2021-26828
CVE-2021-26828
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
OpenPLC ScadaBR exposed arbitrary JSP execution
OpenPLC's ScadaBR allowed remote, authenticated users to upload and execute arbitrary JSP files, leading to potential remote code execution.
Shame score — OpenPLC ScadaBR's unrestricted file upload enabled remote code execution, a severe security flaw actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.