CVE-2021-33538
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.16.18 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wl Bl Ap Cl Eu | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wlt Bl Ap Cl Eu | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wl Bl Ap Cl Us | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wlt Bl Ap Cl Us | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wl Vl Ap Br Cl Eu | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wlt Vl Ap Br Cl Eu | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wl Vl Ap Br Cl Us | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.11.10 |
| Running on/with | Platform Versions |
|---|---|
Weidmueller Ie Wlt Vl Ap Br Cl Us | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.