CVE-2021-26828 is a critical vulnerability affecting OpenPLC ScadaBR on both Linux (through 0.9.1) and Windows (through 1.12.4), allowing remote authenticated attackers to upload and execute arbitrary JSP files. With a CVSS score of 8.8 (High), this flaw presents a significant risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered considerable community discussion and media coverage, despite the absence of public exploit intelligence tools like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.1CPE matchmatch criteria | cpe:2.3:a:scadabr:scadabr:*:*:*:*:*:*:*:* | ||
<= 1.12.4CPE matchmatch criteria | cpe:2.3:a:scadabr:scadabr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.