CVE-2021-20999: WEIDMUELLER: Accidentally open network port in u-controls and IoT-Gateways
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.
Other sources
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-20999?
CVE-2021-20999 is a vulnerability in Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1.
What is the severity of CVE-2021-20999?
The severity of CVE-2021-20999 is 9.8 (Critical).
How can CVE-2021-20999 be exploited?
By exploiting CVE-2021-20999, an attacker can manipulate the device or stop its operation.
Which versions of Weidmüller u-controls and IoT-Gateways are affected by CVE-2021-20999?
Versions up to 1.12.1 of Weidmüller u-controls and IoT-Gateways are affected by CVE-2021-20999.
Is my Weidmüller u-controls or IoT-Gateway vulnerable to CVE-2021-20999?
Your Weidmüller u-controls or IoT-Gateway is vulnerable to CVE-2021-20999 if it runs a version up to 1.12.1.