CVE-2021-20993

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2021-013 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wago:0852-0303_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-0303:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wago:0852-1305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1305:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wago:0852-1505_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1505:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wago:0852-1305\/000-001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1305\/000-001:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wago:0852-1505\/000-001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1505\/000-001:-:*:*:*:*:*:*:*

History

20 May 2021, 19:47

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CPE cpe:2.3:o:wago:0852-1305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-0303:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1505:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:0852-1305\/000-001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:0852-1505_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:0852-1505\/000-001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1505\/000-001:-:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1305\/000-001:-:*:*:*:*:*:*:*
cpe:2.3:o:wago:0852-0303_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wago:0852-1305:-:*:*:*:*:*:*:*
References (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2021-013 - (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2021-013 - Third Party Advisory

Information

Published : 2021-05-13 14:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-20993

Mitre link : CVE-2021-20993

CVE.ORG link : CVE-2021-20993


JSON object : View

Products Affected

wago

  • 0852-0303
  • 0852-0303_firmware
  • 0852-1305_firmware
  • 0852-1305\/000-001_firmware
  • 0852-1305\/000-001
  • 0852-1505\/000-001
  • 0852-1505\/000-001_firmware
  • 0852-1505_firmware
  • 0852-1305
  • 0852-1505
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor