CVE-2021-34560
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD (Secondary)
Description
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.0.9 |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Wha Gw F2d2 0 As Z2 Eth | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.0.9 |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Wha Gw F2d2 0 As Z2 Eth.eip | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.