CVE-2021-34560
published 2021-08-31CVE-2021-34560: In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.21%
10.9th percentile
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pepperl-fuchs | wha-gw-f2d2-0-as-z2-eth.eip_firmware | <= 3.0.9 | — |
| pepperl-fuchs | wha-gw-f2d2-0-as-z2-eth_firmware | <= 3.0.9 | — |
| phoenix_contact | wha-gw-f2d2-0-as_z2-eth | 3.0.9 – 3.0.9 | — |
| phoenix_contact | wha-gw-f2d2-0-as_z2-eth.eip | 3.0.9 – 3.0.9 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2pw-r5rx-m6w6: In PEPPERL+FUCHS WirelessHART-Gateway <= 3
ghsa_unreviewed·2022-05-24
CVE-2021-34560 [MEDIUM] CWE-200 GHSA-f2pw-r5rx-m6w6: In PEPPERL+FUCHS WirelessHART-Gateway <= 3
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
CISA ICS
Pepperl+Fuchs WirelessHART-Gateway
cisa_ics·2022-04-07·CVSS 7.5
[HIGH] Pepperl+Fuchs WirelessHART-Gateway
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Pepperl+Fuchs WirelessHART-Gateway
Last RevisedApril 07, 2022
Alert CodeICSA-22-097-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Pepperl+Fuchs
- Equipment: WirelessHART-Gateway
- Vulnerabilities: Use of Hard-coded Credentials, Uncontrolled Resource Consumption, Reliance on Reverse DNS Resolution for a Security-critical Action, Path Traversal, Cross-site Scripting, Exposure of Sensitive Information to an Unauthorized Actor, Cleartext Storage of Sensitive Information in a Cookie, HTTP Request Smuggling, Sensitive Co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-31
Published