Missing Authentication for Critical Function in Emerson products - CVE-2021-85337
Published: October 6, 2021
Vulnerability identifier: #VU57091
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-85337
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a missing permission validation on system backup restore. A remote authenticated attacker can take over account and change settings.
Affected software
WirelessHART 1410D Gateway
WirelessHART 1420 Gateway
WirelessHART 1410 Gateway
WirelessHART 1420 Gateway
WirelessHART 1410 Gateway
How to mitigate CVE-2021-85337
Install updates from vendor's website.
WirelessHART 1410D Gateway - addressed in versions 4.7.94, 4.7.105
WirelessHART 1420 Gateway - addressed in versions 4.7.94, 4.7.105
WirelessHART 1410 Gateway - addressed in versions 4.7.105, 4.7.94
WirelessHART 1420 Gateway - addressed in versions 4.7.94, 4.7.105
WirelessHART 1410 Gateway - addressed in versions 4.7.105, 4.7.94