Emerson
Emerson Wireless 1420 Gateway Firmware: vulnerabilidades y CVE
Emerson Wireless 1420 Gateway Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-42542 | Alta (8.8) | 1.5% | — | 22 oct 2021 | The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. |
| CVE-2021-42540 | Alta (8.8) | 1.0% | — | 22 oct 2021 | The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality. |
| CVE-2021-42539 | Alta (8.8) | 0.79% | — | 22 oct 2021 | The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change. |
| CVE-2021-42538 | Alta (8.8) | 0.98% | — | 22 oct 2021 | The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. |
| CVE-2021-42536 | Media (6.5) | 0.94% | — | 22 oct 2021 | The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables. |
| CVE-2021-38485 | Alta (8.8) | 0.93% | — | 22 oct 2021 | The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk. |
| CVE-2020-12030 | Crítica (10) | 1.1% | — | 29 sept 2021 | There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in… |
| CVE-2020-19417 | Alta (8.8) | 2.7% | — | 10 mar 2021 | Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application. |
Otros productos de Emerson
Deltav · 15X-stream Enhanced Xegk Firmware · 7Wireless 1410 Gateway Firmware · 7X-stream Enhanced Xefd Firmware · 7X-stream Enhanced Xegp Firmware · 7X-stream Enhanced Xexf Firmware · 7Wireless 1410d Gateway Firmware · 6Valvelink · 6Se4801t0x Redundant Wireless I/O Card Firmware · 6Deltav Workstation · 6Deltav Distributed Control System SQ Controller Firmware · 5Openenterprise Scada Server · 5