CVE-2021-20995

Severity
7.5HIGH
EPSS
0.1%
top 68.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages10 packages

CVEListV5wago/0852-0303unspecifiedV1.2.3.S0
CVEListV5wago/0852-1305unspecifiedV1.1.7.S0
CVEListV5wago/0852-1505unspecifiedV1.1.6.S0
CVEListV5wago/0852-1305/000-001unspecifiedV1.0.4.S0
CVEListV5wago/0852-1505/000-001unspecifiedV1.0.4.S0

🔴Vulnerability Details

2
GHSA
GHSA-h3wh-323m-4h77: In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials2022-05-24
CVEList
WAGO: Managed Switches: Storage of user credentials in a cookie2021-05-13
CVE-2021-20995 (HIGH CVSS 7.5) | In multiple managed switches by WAG | cvebase.io