smartptt CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

smartptt vulnerability overview

Aggregates CVE and security vulnerability intelligence across all smartptt-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-30459 SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default). [email protected] 7.2 33.46% 2023-04-14 2025-02-06
CVE-2021-43938 Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization. [email protected] 8.1 0.21% 2022-04-29 2024-11-21
CVE-2021-43937 Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. [email protected] 7.6 0.07% 2022-04-29 2024-11-21
CVE-2021-43939 Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints. [email protected] 8.8 0.08% 2022-04-28 2024-11-21
CVE-2021-43934 Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files. [email protected] 9.8 0.25% 2022-04-28 2024-11-21
CVE-2021-43932 Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. [email protected] 9.0 0.19% 2022-04-28 2024-11-21
CVE-2021-43930 Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system. [email protected] 4.9 0.25% 2022-04-28 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence