Lucene search

K
cveSiemensCVE-2021-41543
HistoryMar 08, 2022 - 12:15 p.m.

CVE-2021-41543

2022-03-0812:15:10
CWE-532
CWE-284
siemens
web.nvd.nist.gov
67
vulnerability
climatix pol909
awb module
awm module
information disclosure
nvd
cve-2021-41543

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

35.0%

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.

Affected configurations

Nvd
Node
siemensclimatix_pol909_firmwareRange<11.36advanced_web_module
OR
siemensclimatix_pol909_firmwareRange<11.44advanced_web_and_bacnet_module
AND
siemensclimatix_pol909Match-
VendorProductVersionCPE
siemensclimatix_pol909_firmware*cpe:2.3:o:siemens:climatix_pol909_firmware:*:*:*:*:advanced_web_module:*:*:*
siemensclimatix_pol909_firmware*cpe:2.3:o:siemens:climatix_pol909_firmware:*:*:*:*:advanced_web_and_bacnet_module:*:*:*
siemensclimatix_pol909-cpe:2.3:h:siemens:climatix_pol909:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Climatix POL909 (AWB module)",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V11.44"
      }
    ]
  },
  {
    "product": "Climatix POL909 (AWM module)",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V11.36"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

35.0%

Related for CVE-2021-41543