CVE-2021-38485
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7.94 |
| Running on/with | Platform Versions |
|---|---|
Emerson Wireless 1410 Gateway | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7.94 |
| Running on/with | Platform Versions |
|---|---|
Emerson Wireless 1410d Gateway | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7.94 |
| Running on/with | Platform Versions |
|---|---|
Emerson Wireless 1420 Gateway | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.