TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-20999

CRITICAL
9.4

Descricao

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

Detalhes CVE

Pontuacao CVSS v3.19.4
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado5/13/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

weidmueller:iot-gw30weidmueller:iot-gw30-4g-euweidmueller:iot-gw30-4g-eu_firmwareweidmueller:iot-gw30_firmwareweidmueller:uc20-wl2000-acweidmueller:uc20-wl2000-ac_firmwareweidmueller:uc20-wl2000-iotweidmueller:uc20-wl2000-iot_firmware

Fraquezas (CWE)

CWE-668

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.