CVE-2021-34561

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:10

Type Values Removed Values Added
References () https://cert.vde.com/en-us/advisories/vde-2021-027 - Third Party Advisory () https://cert.vde.com/en-us/advisories/vde-2021-027 - Third Party Advisory
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 7.5

Information

Published : 2021-08-31 11:15

Updated : 2024-11-21 06:10


NVD link : CVE-2021-34561

Mitre link : CVE-2021-34561

CVE.ORG link : CVE-2021-34561


JSON object : View

Products Affected

pepperl-fuchs

  • wha-gw-f2d2-0-as-z2-eth.eip_firmware
  • wha-gw-f2d2-0-as-z2-eth
  • wha-gw-f2d2-0-as-z2-eth_firmware
  • wha-gw-f2d2-0-as-z2-eth.eip
CWE
CWE-350

Reliance on Reverse DNS Resolution for a Security-Critical Action