CVE-2021-33537: WEIDMUELLER: WLAN devices affected by Remote Code Execution (RCE) vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iwwebs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33537 vulnerability?
CVE-2021-33537 is a remote code execution vulnerability in Weidmueller Industrial WLAN devices in multiple versions.
How severe is CVE-2021-33537 vulnerability?
CVE-2021-33537 vulnerability has a severity score of 8.8 (high).
How does CVE-2021-33537 vulnerability occur?
CVE-2021-33537 vulnerability occurs due to an overflow of an error message buffer when parsing the iw_webs configuration in Weidmueller Industrial WLAN devices.
Which versions of Weidmueller Industrial WLAN devices are affected by CVE-2021-33537 vulnerability?
CVE-2021-33537 vulnerability affects the following versions of Weidmueller Industrial WLAN devices: Ie-wl-bl-ap-cl-eu Firmware up to and including 1.16.18, Ie-wlt-bl-ap-cl-eu Firmware up to and including 1.16.18, Ie-wl-bl-ap-cl-us Firmware up to and including 1.16.18, Ie-wlt-bl-ap-cl-us Firmware up to and including 1.16.18, Ie-wl-vl-ap-br-cl-eu Firmware up to and including 1.16.18, Ie-wlt-vl-ap-br-cl-eu Firmware up to and including 1.16.18, Ie-wl-vl-ap-br-cl-us Firmware up to and including 1.16.18, Ie-wlt-vl-ap-br-cl-us Firmware up to and including 1.16.18, Ie-wl-bl-ap-cl-eu Firmware up to and including 1.11.10, Ie-wlt-bl-ap-cl-eu Firmware up to and including 1.11.10, Ie-wl-bl-ap-cl-us Firmware up to and including 1.11.10, Ie-wlt-bl-ap-cl-us Firmware up to and including 1.11.10, Ie-wl-vl-ap-br-cl-eu Firmware up to and including 1.11.10, and Ie-wlt-vl-ap-br-cl-eu Firmware up to and including 1.11.10.
How can I fix the CVE-2021-33537 vulnerability?
To fix the CVE-2021-33537 vulnerability, it is recommended to update your Weidmueller Industrial WLAN devices to a version higher than 1.16.18 or 1.11.10, depending on the affected firmware.