VYPR

Wha Gw F2d2 0 As Z2 Eth Firmware

by Pepperl Fuchs

CVEs (5)

  • CVE-2021-34565CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

  • CVE-2021-34561HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying…

  • CVE-2021-33555HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

  • CVE-2021-34560MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

  • CVE-2021-34559MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.