---
cve: "CVE-2021-43936"
severity: "CRITICAL"
cvss: 9.8
epss: "79.5%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2021-12-06 18:15:08"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T01:18:13+02:00"
---

# CVE-2021-43936

> 9.8 CRITICAL

## Beschreibung

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-50589 — WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)](https://www.exploit-db.com/exploits/50589)

## Referenzen

- <http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html>
- <https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-43936) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
