Description
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 4), Totally Integrated Automation Portal (TIA Portal) V20 (All versions < V20 Update 3). The affected application improperly handles uploaded projects in the document root. This could allow an attacker with contributor privileges to cause denial of service by uploading a malicious project.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Product status
Any version before V2.1.1
Any version before *
Any version before *
Any version before *
Any version before V19 Update 4
Any version before V20 Update 3
References
cert-portal.siemens.com/productcert/html/ssa-460466.html