CVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.8
- EPSS
- 39.1% 백분위 98.4% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.12.24
- 공개일
- 2021.06.11
CISA KEV에 등록된 실제 악용 확인 취약점
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
공급사 OpenPLC
제품 ScadaBR
영향 버전 n/a, <= 0.9.1, <= 1.12.4
수정 버전 공식 출처에서 확인 필요
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.12.24CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-434
KEV 등록일 2025.12.03
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/2174 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26828
EPSS 데이터 기준일 2026.06.27