Improper access control in Emerson products - CVE-2020-12030
Published: May 15, 2020
Wireless 1410 Gateway
Wireless 1420 Gateway
Wireless 1552WU Gateway
Emerson
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway. A remote attacker can issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.