Vulnerability Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu | - |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu | - |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Bl-Ap-Cl-Us | - |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us | - |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu | - |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu | - |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us | - |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | <= 1.16.18 |
| Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en-us/advisories/vde-2021-026Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-026Third Party Advisory
FAQ
What is CVE-2021-33539?
CVE-2021-33539 is a vulnerability with a CVSS score of 7.2 (HIGH). In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the d...
How severe is CVE-2021-33539?
CVE-2021-33539 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33539?
Check the references section above for vendor advisories and patch information. Affected products include: Weidmueller Ie-Wl-Bl-Ap-Cl-Eu Firmware, Weidmueller Ie-Wl-Bl-Ap-Cl-Eu, Weidmueller Ie-Wlt-Bl-Ap-Cl-Eu Firmware, Weidmueller Ie-Wlt-Bl-Ap-Cl-Eu, Weidmueller Ie-Wl-Bl-Ap-Cl-Us Firmware.