// For flags

CVE-2021-20999

WEIDMUELLER: Accidentally open network port in u-controls and IoT-Gateways

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

En Weidmüller u-controls and IoT-Gateway en versiones hasta 1.12.1, se puede acceder accidentalmente a un puerto de red destinado únicamente para uso interno del dispositivo por medio de interfaces de red externas. Al explotar esta vulnerabilidad, el dispositivo puede ser manipulado o la operación puede ser detenida

*Credits: Reported by Weidmüller.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-05-13 CVE Published
  • 2024-01-27 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (1)
URL Tag Source
https://cert.vde.com/en-us/advisories/vde-2021-016 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware"
>= 1.3.0 < 1.9.1
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware" and version " >= 1.3.0 < 1.9.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac
Search vendor "Weidmueller" for product "Uc20-wl2000-ac"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware"
>= 1.10.0 < 1.10.3
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware" and version " >= 1.10.0 < 1.10.3"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac
Search vendor "Weidmueller" for product "Uc20-wl2000-ac"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware"
1.11.0
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware" and version "1.11.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac
Search vendor "Weidmueller" for product "Uc20-wl2000-ac"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware"
1.12.1
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware" and version "1.12.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac
Search vendor "Weidmueller" for product "Uc20-wl2000-ac"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware"
>= 1.3.0 < 1.9.1
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware" and version " >= 1.3.0 < 1.9.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot
Search vendor "Weidmueller" for product "Uc20-wl2000-iot"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware"
>= 1.10.0 < 1.10.3
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware" and version " >= 1.10.0 < 1.10.3"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot
Search vendor "Weidmueller" for product "Uc20-wl2000-iot"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware"
1.11.0
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware" and version "1.11.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot
Search vendor "Weidmueller" for product "Uc20-wl2000-iot"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware"
1.12.1
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware" and version "1.12.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot
Search vendor "Weidmueller" for product "Uc20-wl2000-iot"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30 Firmware
Search vendor "Weidmueller" for product "Iot-gw30 Firmware"
>= 1.3.0 < 1.9.1
Search vendor "Weidmueller" for product "Iot-gw30 Firmware" and version " >= 1.3.0 < 1.9.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30
Search vendor "Weidmueller" for product "Iot-gw30"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30 Firmware
Search vendor "Weidmueller" for product "Iot-gw30 Firmware"
>= 1.10.0 < 1.10.3
Search vendor "Weidmueller" for product "Iot-gw30 Firmware" and version " >= 1.10.0 < 1.10.3"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30
Search vendor "Weidmueller" for product "Iot-gw30"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30 Firmware
Search vendor "Weidmueller" for product "Iot-gw30 Firmware"
1.11.0
Search vendor "Weidmueller" for product "Iot-gw30 Firmware" and version "1.11.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30
Search vendor "Weidmueller" for product "Iot-gw30"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30 Firmware
Search vendor "Weidmueller" for product "Iot-gw30 Firmware"
1.12.1
Search vendor "Weidmueller" for product "Iot-gw30 Firmware" and version "1.12.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30
Search vendor "Weidmueller" for product "Iot-gw30"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu Firmware
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware"
>= 1.3.0 < 1.9.1
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware" and version " >= 1.3.0 < 1.9.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu Firmware
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware"
>= 1.10.0 < 1.10.3
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware" and version " >= 1.10.0 < 1.10.3"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu Firmware
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware"
1.11.0
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware" and version "1.11.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu Firmware
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware"
1.12.1
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware" and version "1.12.1"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu"
--
Safe