PT-2021-20185 · Weidmueller · Weidmueller Industrial Wlan

Published

2021-06-25

·

Updated

2022-10-25

·

CVE-2021-33538

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Weidmueller Industrial WLAN devices (affected versions not specified)
Description The issue concerns an improper access control vulnerability in the account settings functionality of the device. Specifically, it affects the iw webs account settings. A specially crafted username entry can lead to the overwrite of an existing user account password, allowing remote shell access to the device as that user. An attacker, authenticated as a low-privilege user, can trigger this issue by sending specific commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-33538

Affected Products

Weidmueller Industrial Wlan