CVE Vulnerabilities

CVE-2021-33528

Improper Adherence to Coding Standards

Published: Jun 25, 2021 | Modified: Jul 27, 2021
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Weakness

The product does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

Affected Software

Name Vendor Start Version End Version
Ie-wl-bl-ap-cl-eu_firmware Weidmueller * 1.16.18 (including)

Potential Mitigations

References