CVE Vulnerabilities

CVE-2021-42540

Write-what-where Condition

Published: Oct 22, 2021 | Modified: Oct 28, 2021
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

Weakness

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Affected Software

Name Vendor Start Version End Version
Wireless_1410_gateway_firmware Emerson * 4.7.94 (excluding)

Potential Mitigations

References