CVE-2021-20999
Published May 13, 2021
Last updated a year ago
Overview
- Description
- In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.
- Source
- info@cert.vde.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- info@cert.vde.com
- CWE-668
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-ac_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A1E7682-E240-4D15-AC34-626C77BE41B1", "versionEndExcluding": "1.9.1", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-ac_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FF8472B-BBE3-4793-AF5F-E3AB4FB3D0E1", "versionEndExcluding": "1.10.3", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-ac_firmware:1.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AF70A61-6C4A-4B07-B263-5E19CBCAD607" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-ac_firmware:1.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A69023EC-EFA5-444C-9636-9855565AFF80" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:weidmueller:uc20-wl2000-ac:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "BAD85D18-1A66-487D-80B3-C5E1285685DD" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-iot_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3AE0D482-A42D-4545-A5C5-15B0ADD36A8C", "versionEndExcluding": "1.9.1", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-iot_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00BD211A-944F-4074-9605-A78FFEB9F375", "versionEndExcluding": "1.10.3", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-iot_firmware:1.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3567D99A-8FC6-4663-8BFB-7AC1B5718D74" }, { "criteria": "cpe:2.3:o:weidmueller:uc20-wl2000-iot_firmware:1.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52E0A330-8B6D-4610-9F90-AA455E0C30A7" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:weidmueller:uc20-wl2000-iot:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B98578B6-9F39-4616-A240-0A09832A0A92" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:weidmueller:iot-gw30_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D37EA6C-392B-404D-8A2D-2038D45B9736", "versionEndExcluding": "1.9.1", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82C07A83-6181-40D6-BAC5-0BFD2EB0775F", "versionEndExcluding": "1.10.3", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30_firmware:1.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D00D166-D270-4CA8-AF12-D00E936C09D2" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30_firmware:1.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "799AAC8C-E0D9-4C56-A46E-5833E2FF4F36" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:weidmueller:iot-gw30:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B247B94B-4845-4FCC-81E1-4880A7B2B0FE" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:weidmueller:iot-gw30-4g-eu_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF37BFDC-99AC-4FE6-AE00-AAE5BCBC9A35", "versionEndExcluding": "1.9.1", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30-4g-eu_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01983454-B4AE-4C7A-BC09-705FF0F1DB2B", "versionEndExcluding": "1.10.3", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30-4g-eu_firmware:1.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6850EBC4-41BB-4845-9A87-AE3E7D9061B8" }, { "criteria": "cpe:2.3:o:weidmueller:iot-gw30-4g-eu_firmware:1.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B93938B2-19B4-46D6-AB0B-1BC4FE559D91" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:weidmueller:iot-gw30-4g-eu:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4BD44BDA-E67A-4088-AF77-55C0BEC5782B" } ], "operator": "OR" } ], "operator": "AND" } ]