PT-2021-5144 · Emerson · Emerson Wirelesshart Gateway
Published
2021-10-05
·
Updated
2021-10-05
·
CVE-2021-85337
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Emerson WirelessHART Gateway versions 1420, 1410D, and 1410
Description
The issue is related to a lack of access control checks during system restore from a backup, which can be exploited by a remote attacker to bypass security restrictions, gain unauthorized access to protected information, and modify settings.
Recommendations
For Emerson WirelessHART Gateway versions 1420, 1410D, and 1410, consider implementing additional access control checks during system restore from a backup to prevent unauthorized access.
As a temporary workaround, restrict remote access to the system until a proper fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emerson Wirelesshart Gateway