← Back

CVE-2021-38485

nvd nist
Published: Oct 22, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.

Affected (3)

3 products
Wireless 1410 Gateway Firmware
Wireless 1410d Gateway Firmware
Wireless 1420 Gateway Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.7.94
Running on/withPlatform Versions
Emerson
Wireless 1410 Gateway
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.7.94
Running on/withPlatform Versions
Emerson
Wireless 1410d Gateway
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.7.94
Running on/withPlatform Versions
Emerson
Wireless 1420 Gateway
All versions

References (2)

Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.