Required CVE Record Information
Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
8.8 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Product Status
Learn moreVersions 4 Total
Default Status: unknown
affected
Versions 4 Total
Default Status: unknown
affected
References 1 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- https://cert.vde.com/en-us/advisories/vde-2021-026 x_transferred