CVE-2021-31630

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
03/08/2021
Last modified:
03/05/2022

Description

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openplcproject:openplc_v3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:openplcproject:openplc_v3:-:*:*:*:*:*:*:*