8.8
CVE-2021-33537
- EPSS 2.26%
- Published 25.06.2021 19:15:09
- Last modified 21.11.2024 06:09:02
- Source info@cert.vde.com
- Teams watchlist Login
- Open Login
In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Data is provided by the National Vulnerability Database (NVD)
Weidmueller ≫ Ie-wl-bl-ap-cl-eu Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wlt-bl-ap-cl-eu Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wl-bl-ap-cl-us Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wlt-bl-ap-cl-us Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wl-vl-ap-br-cl-eu Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wlt-vl-ap-br-cl-eu Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wl-vl-ap-br-cl-us Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wlt-vl-ap-br-cl-us Firmware Version <= 1.16.18
Weidmueller ≫ Ie-wl-bl-ap-cl-eu Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wlt-bl-ap-cl-eu Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wl-bl-ap-cl-us Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wlt-bl-ap-cl-us Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wl-vl-ap-br-cl-eu Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wlt-vl-ap-br-cl-eu Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wl-vl-ap-br-cl-us Firmware Version <= 1.11.10
Weidmueller ≫ Ie-wlt-vl-ap-br-cl-us Firmware Version <= 1.11.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.26% | 0.831 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
info@cert.vde.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.