CVE Vulnerabilities

CVE-2021-20999

Published: May 13, 2021 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

Affected Software

Name Vendor Start Version End Version
Uc20-wl2000-ac_firmware Weidmueller 1.3.0 (including) 1.9.1 (excluding)
Uc20-wl2000-ac_firmware Weidmueller 1.10.0 (including) 1.10.3 (excluding)
Uc20-wl2000-ac_firmware Weidmueller 1.11.0 (including) 1.11.0 (including)
Uc20-wl2000-ac_firmware Weidmueller 1.12.1 (including) 1.12.1 (including)

References