CVE-2021-20993
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.3.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 0852 0303 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.1.7.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 0852 1305 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.1.6.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 0852 1505 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.4.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 0852 1305/000 001 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.4.s0 |
| Running on/with | Platform Versions |
|---|---|
Wago 0852 1505/000 001 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.