CVE-2021-33538
WEIDMUELLER: WLAN devices affected by improper access control vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
En los dispositivos Weidmueller Industrial WLAN en múltiples versiones, se presenta una vulnerabilidad explotable de control de acceso inapropiado en la funcionalidad account settings iw_webs. Una entrada de nombre de usuario especialmente diseñada puede causar la sobreescritura de una contraseña de cuenta de usuario existente, resultando en un acceso de shell remoto al dispositivo como ese usuario. Un atacante puede enviar comandos mientras está autenticado como un usuario poco privilegiado para desencadenar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-24 CVE Reserved
- 2021-06-25 CVE Published
- 2024-09-16 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en-us/advisories/vde-2021-026 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" | <= 1.16.18 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" and version " <= 1.16.18" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wl-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-bl-ap-cl-us Search vendor "Weidmueller" for product "Ie-wlt-bl-ap-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-eu Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-eu" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wl-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wl-vl-ap-br-cl-us" | - | - |
Safe
|
Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Firmware Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" | <= 1.11.10 Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us Firmware" and version " <= 1.11.10" | - |
Affected
| in | Weidmueller Search vendor "Weidmueller" | Ie-wlt-vl-ap-br-cl-us Search vendor "Weidmueller" for product "Ie-wlt-vl-ap-br-cl-us" | - | - |
Safe
|