PT-2021-5144 · Emerson · Emerson Wirelesshart Gateway

Published

2021-10-05

·

Updated

2021-10-05

·

CVE-2021-85337

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Emerson WirelessHART Gateway versions 1420, 1410D, and 1410
Description The issue is related to a lack of access control checks during system restore from a backup, which can be exploited by a remote attacker to bypass security restrictions, gain unauthorized access to protected information, and modify settings.
Recommendations For Emerson WirelessHART Gateway versions 1420, 1410D, and 1410, consider implementing additional access control checks during system restore from a backup to prevent unauthorized access. As a temporary workaround, restrict remote access to the system until a proper fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05938
CVE-2021-85337

Affected Products

Emerson Wirelesshart Gateway