9
CVSSv2

CVE-2021-33538

Published: 25/06/2021 Updated: 25/10/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

weidmueller ie-wl-bl-ap-cl-eu_firmware

weidmueller ie-wlt-bl-ap-cl-eu_firmware

weidmueller ie-wl-bl-ap-cl-us_firmware

weidmueller ie-wlt-bl-ap-cl-us_firmware

weidmueller ie-wl-vl-ap-br-cl-eu_firmware

weidmueller ie-wlt-vl-ap-br-cl-eu_firmware

weidmueller ie-wl-vl-ap-br-cl-us_firmware

weidmueller ie-wlt-vl-ap-br-cl-us_firmware