VulnerabilityModified
CVE-2021-34560
The stored credentials can be captured by an attacker who gains control over the user's computer.
MEDIUM 5.5EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- pepperl-fuchs/wha-gw-f2d2-0-as-z2-eth firmware · pepperl-fuchs/wha-gw-f2d2-0-as-z2-eth.eip firmware
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en-us/advisories/vde-2021-027Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-027Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.