Vulnerabilities > Smartptt > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-04-29 CVE-2021-43938 Missing Authorization vulnerability in Smartptt Scada Server 1.4
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.
network
low complexity
smartptt CWE-862
critical
9.8
2022-04-28 CVE-2021-43934 Unspecified vulnerability in Smartptt Scada 1.1
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.
network
low complexity
smartptt
critical
9.8