CVE-2021-38485

The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-278-02 Patch Third Party Advisory US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-278-02 Patch Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:emerson:wireless_1410_gateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:wireless_1410_gateway:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:emerson:wireless_1410d_gateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:wireless_1410d_gateway:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:emerson:wireless_1420_gateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:wireless_1420_gateway:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:17

Type Values Removed Values Added
References () https://us-cert.cisa.gov/ics/advisories/icsa-21-278-02 - Patch, Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-21-278-02 - Patch, Third Party Advisory, US Government Resource
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 8.0

Information

Published : 2021-10-22 14:15

Updated : 2024-11-21 06:17


NVD link : CVE-2021-38485

Mitre link : CVE-2021-38485

CVE.ORG link : CVE-2021-38485


JSON object : View

Products Affected

emerson

  • wireless_1420_gateway
  • wireless_1420_gateway_firmware
  • wireless_1410_gateway
  • wireless_1410d_gateway
  • wireless_1410_gateway_firmware
  • wireless_1410d_gateway_firmware
CWE
CWE-20

Improper Input Validation