QID 590582
Date Published: 2021-12-23
QID 590582: Emerson WirelessHART Gateway Improper Access Control Vulnerability (ICSA-20-135-02)
AFFECTED PRODUCTS
Emerson reports that the vulnerability affects the following products when the VLAN feature is enabled:
Wireless 1410 Gateway, revisions 4.6.43 to 4.7.84
Wireless 1420 Gateway, revisions 4.6.43 to 4.7.84
Wireless 1552WU Gateway, revisions 4.6.43 to 4.7.84
Note that this is not an issue with the WirelessHART communication protocol. Wireless field devices, Smart Wireless Field Link, AMS Wireless SNAP-ON, and AMS Wireless Configurator are unaffected.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could disable the internal gateway firewall. Once the gateway's firewall is disabled, a malicious user could issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.
Customers are advised to refer to CERT MITIGATIONS section ICSA-20-135-02 for affected packages and patching details.
- ICSA-20-135-02 -
www.us-cert.gov/ics/advisories/ICSA-20-135-02
CVEs related to QID 590582
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-20-135-02 |
|