CVE-2021-45420
Published on: Not Yet Published
Last Modified on: 07/12/2022 05:42:00 PM UTC
Certain versions of Dixell Xweb-500 from Emerson contain the following vulnerability:
** UNSUPPORTED WHEN ASSIGNED ** Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.
- CVE-2021-45420 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vulnerability Report Emerson – Dixell XWEB-500 Multiple Vulnerabilities - Swascan | www.swascan.com text/html |
![]() |
Dixell | Emerson GB | dixell.com text/html |
![]() |
Emerson Global | Emerson | emerson.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Emerson | Dixell Xweb-500 | - | All | All | All |
Operating System | Emerson | Dixell Xweb-500 Firmware | - | All | All | All |
- cpe:2.3:h:emerson:dixell_xweb-500:-:*:*:*:*:*:*:*:
- cpe:2.3:o:emerson:dixell_xweb-500_firmware:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-45420 : Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/… twitter.com/i/web/status/1… | 2022-02-14 14:09:37 |
![]() |
CVE-2021-45420 | 2022-02-14 15:38:04 |