Vulnerability Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu | - |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu | - |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Us | - |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us | - |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu | - |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu | - |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us | - |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en-us/advisories/vde-2021-026Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-026Third Party Advisory
FAQ
What is CVE-2021-33535?
CVE-2021-33535 is a vulnerability with a CVSS score of 8.8 (HIGH). In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can ...
How severe is CVE-2021-33535?
CVE-2021-33535 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33535?
Check the references section above for vendor advisories and patch information. Affected products include: Weidmueller Ie-Wl-Bl-Ap-Cl-Eu Firmware, Weidmueller Ie-Wl-Bl-Ap-Cl-Eu, Weidmueller Ie-Wlt-Bl-Ap-Cl-Eu Firmware, Weidmueller Ie-Wlt-Bl-Ap-Cl-Eu, Weidmueller Ie-Wl-Bl-Ap-Cl-Us Firmware.