Pepperl-fuchs
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth Firmware: vulnerabilidades y CVE
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-34565 | Crítica (9.8) | 1.0% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. |
| CVE-2021-34564 | Media (5.5) | 0.15% | — | 31 ago 2021 | Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9. |
| CVE-2021-34563 | Baja (3.3) | 0.24% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. |
| CVE-2021-34562 | Media (6.1) | 0.58% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. |
| CVE-2021-34561 | Alta (8.8) | 0.87% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall… |
| CVE-2021-34560 | Media (5.5) | 0.21% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the… |
| CVE-2021-34559 | Media (5.3) | 0.77% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings. |
| CVE-2021-33555 | Alta (7.5) | 1.2% | — | 31 ago 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. |