Back to Database
Status published
High
CVE-2021-43938
Elcomplus SmartPTT SCADA Server Information Exposure
Vulnerability Description
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-43938
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Heinzl reported these vulnerabilities to CISA.
More from Elcomplus
View All →CVE-2022-2140
Elcomplus SmartICS Cross-site Scripting
High
8.8
CVE-2022-2106
Elcomplus SmartICS Path Traversal
Low
3.8
CVE-2022-2088
Elcomplus SmartICS Access Control
Medium
6.8
CVE-2021-43939
Elcomplus SmartPtt Improper Authorization
High
8.8
CVE-2021-43937
Elcomplus SmartPTT SCADA Server Cross-site Request Forgery
High
7.6
Affected Vendor
Elcomplus
View all reports →Affected Software
SmartPTT SCADA Server
Vulnerable Versions:
1.4
Timeline
Official Publish:
April 29th, 2022
Last Modified:
April 16th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H