CVE-2021-33533
WEIDMUELLER: WLAN devices affected by OS Command Injection vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
En los dispositivos Weidmueller Industrial WLAN en múltiples versiones, se presenta una vulnerabilidad de inyección de comandos explotable en la funcionalidad iw_webs. Un parámetro iw_serverip especialmente diseñado puede causar a una entrada del usuario sea reflejada en una llamada subsiguiente de iw_system, resultando en un control remoto sobre el dispositivo. Un atacante puede enviar comandos mientras está autenticado como un usuario poco privilegiado para desencadenar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-24 CVE Reserved
- 2021-06-25 CVE Published
- 2024-04-03 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en-us/advisories/vde-2021-026 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us" | - | - |
Safe
|