Industrial WLAN
by Weidmueller
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33539 | 0.00 | — | 0.00 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a… | |||
| CVE-2021-33538 | 0.00 | — | 0.00 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in… | |||
| CVE-2021-33537 | 0.00 | — | 0.02 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote… | |||
| CVE-2021-33536 | 0.00 | — | 0.00 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in ServiceAgent functionality. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds… | |||
| CVE-2021-33535 | 0.00 | — | 0.02 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code… | |||
| CVE-2021-33534 | 0.00 | — | 0.04 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full… | |||
| CVE-2021-33533 | 0.00 | — | 0.06 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote… | |||
| CVE-2021-33532 | 0.00 | — | 0.06 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in… | |||
| CVE-2021-33531 | 0.00 | — | 0.00 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic… | |||
| CVE-2021-33530 | 0.00 | — | 0.05 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed,… | |||
| CVE-2021-33529 | 0.00 | — | 0.00 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device. | |||
| CVE-2021-33528 | 0.00 | — | 0.01 | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root… |
- CVE-2021-33539Jun 25, 2021risk 0.00cvss —epss 0.00
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a…
- CVE-2021-33538Jun 25, 2021risk 0.00cvss —epss 0.00
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in…
- CVE-2021-33537Jun 25, 2021risk 0.00cvss —epss 0.02
In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote…
- CVE-2021-33536Jun 25, 2021risk 0.00cvss —epss 0.00
In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in ServiceAgent functionality. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds…
- CVE-2021-33535Jun 25, 2021risk 0.00cvss —epss 0.02
In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code…
- CVE-2021-33534Jun 25, 2021risk 0.00cvss —epss 0.04
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full…
- CVE-2021-33533Jun 25, 2021risk 0.00cvss —epss 0.06
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote…
- CVE-2021-33532Jun 25, 2021risk 0.00cvss —epss 0.06
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in…
- CVE-2021-33531Jun 25, 2021risk 0.00cvss —epss 0.00
In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic…
- CVE-2021-33530Jun 25, 2021risk 0.00cvss —epss 0.05
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed,…
- CVE-2021-33529Jun 25, 2021risk 0.00cvss —epss 0.00
In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.
- CVE-2021-33528Jun 25, 2021risk 0.00cvss —epss 0.01
In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root…