Description
An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise.
Problem types
Product status
Any version
3.0.11.5 BN10
Credits
Piotr Kijewski of the Shadowserver Foundation reported these vulnerabilities to CISA.
References
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-100-01