SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33538

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality.

HIGH 8.8EPSS 1.05%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.05% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
weidmueller/ie-wl-bl-ap-cl-eu firmware · weidmueller/ie-wlt-bl-ap-cl-eu firmware · weidmueller/ie-wl-bl-ap-cl-us firmware · weidmueller/ie-wlt-bl-ap-cl-us firmware · weidmueller/ie-wl-vl-ap-br-cl-eu firmware · weidmueller/ie-wlt-vl-ap-br-cl-eu firmware · weidmueller/ie-wl-vl-ap-br-cl-us firmware · weidmueller/ie-wlt-vl-ap-br-cl-us firmware
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.