Lucene search

K
cvelistCERTVDECVELIST:CVE-2021-20994
HistoryMay 13, 2021 - 1:45 p.m.

CVE-2021-20994 WAGO: Managed Switches: Reflected Cross-site Scripting

2021-05-1313:45:24
CWE-79
CERTVDE
www.cve.org
6
cve-2021-20994
wago
managed switches
reflected cross-site scripting
web-based management
attacker
malicious code

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

33.8%

In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.

CNA Affected

[
  {
    "product": "0852-0303",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "V1.2.3.S0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "0852-1305",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "V1.1.7.S0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "0852-1505",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "V1.1.6.S0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "0852-1305/000-001",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "V1.0.4.S0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "0852-1505/000-001",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "V1.0.4.S0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

33.8%

Related for CVELIST:CVE-2021-20994