CVE-2021-20994: WAGO: Managed Switches: Reflected Cross-site Scripting
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-20994?
CVE-2021-20994 is a vulnerability found in multiple managed switches by WAGO that allows an attacker to inject possible malicious code into the Web-Based Management.
How does CVE-2021-20994 affect WAGO 0852-0303 Firmware?
CVE-2021-20994 affects WAGO 0852-0303 Firmware versions up to and including 1.2.3.s0.
How can an attacker exploit CVE-2021-20994?
An attacker can exploit CVE-2021-20994 by tricking a legitimate user into clicking a link that injects possible malicious code into the Web-Based Management.
What is the severity of CVE-2021-20994?
CVE-2021-20994 has a severity rating of 6.1 (High).
Where can I find more information about CVE-2021-20994?
You can find more information about CVE-2021-20994 at the following reference: https://cert.vde.com/en-us/advisories/vde-2021-013