QID 590582

Date Published: 2021-12-23

QID 590582: Emerson WirelessHART Gateway Improper Access Control Vulnerability (ICSA-20-135-02)

AFFECTED PRODUCTS
Emerson reports that the vulnerability affects the following products when the VLAN feature is enabled:
Wireless 1410 Gateway, revisions 4.6.43 to 4.7.84
Wireless 1420 Gateway, revisions 4.6.43 to 4.7.84
Wireless 1552WU Gateway, revisions 4.6.43 to 4.7.84
Note that this is not an issue with the WirelessHART communication protocol. Wireless field devices, Smart Wireless Field Link, AMS Wireless SNAP-ON, and AMS Wireless Configurator are unaffected.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could disable the internal gateway firewall. Once the gateway's firewall is disabled, a malicious user could issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-135-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590582

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-135-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-135-02