CVE-2021-20993

Severity
5.3MEDIUM
EPSS
0.2%
top 53.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages10 packages

CVEListV5wago/0852-0303unspecifiedV1.2.3.S0
CVEListV5wago/0852-1305unspecifiedV1.1.7.S0
CVEListV5wago/0852-1505unspecifiedV1.1.6.S0
CVEListV5wago/0852-1305/000-001unspecifiedV1.0.4.S0
CVEListV5wago/0852-1505/000-001unspecifiedV1.0.4.S0

🔴Vulnerability Details

2
GHSA
GHSA-8xqw-xjxh-7m7j: In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources locate2022-05-24
CVEList
WAGO: Managed Switches: Exposure of sensitive information through directory listing2021-05-13
CVE-2021-20993 (MEDIUM CVSS 5.3) | In multiple managed switches by WAG | cvebase.io