PT-2021-20545 · Pepperl+Fuchs · Wirelesshart Gateway

Published

2021-08-31

·

Updated

2022-09-29

·

CVE-2021-34560

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PEPPERL+FUCHS WirelessHART-Gateway versions 3.0.9 and earlier
Description: A form in the affected software contains a password field with autocomplete enabled, allowing stored credentials to be captured by an attacker who gains control over the user's computer. This can occur if the user has logged in at least once.
Recommendations: For PEPPERL+FUCHS WirelessHART-Gateway versions 3.0.9 and earlier, consider disabling the autocomplete feature for password fields as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34560

Affected Products

Wirelesshart Gateway