// For flags

CVE-2021-34605

Xinje XD/E Series PLC Program Tool Zip Slip

Severity Score

7.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

Una vulnerabilidad de deslizamiento de zip en XINJE XD/E Series PLC Program Tool versiones hasta v3.5.1, puede proporcionar a un atacante privilegios de escritura de archivos arbitrarios cuando abre un archivo de proyecto especialmente diseñado. Esta vulnerabilidad puede ser desencadenada al abrir manualmente un archivo de proyecto infectado, o al iniciar una petición de carga de programa desde un PLC Xinje infectado. Esto puede resultar en una ejecución de código remota, una divulgación de información y una denegación de servicio del sistema que ejecuta XINJE XD/E Series PLC Program Tool

*Credits: Mashav Sapir of Claroty
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-10 CVE Reserved
  • 2022-05-11 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-23: Relative Path Traversal
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xinje
Search vendor "Xinje"
Xd\/e Series Plc Program Tool
Search vendor "Xinje" for product "Xd\/e Series Plc Program Tool"
<= 3.5.1
Search vendor "Xinje" for product "Xd\/e Series Plc Program Tool" and version " <= 3.5.1"
-
Affected