CVE-2021-33539: WEIDMUELLER: WLAN devices affected by authentication bypass vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33539?
CVE-2021-33539 is a vulnerability in Weidmueller Industrial WLAN devices that allows an authentication bypass through hostname processing.
What is the severity of CVE-2021-33539?
CVE-2021-33539 has a severity rating of 7.2 (high).
How does CVE-2021-33539 affect Weidmueller Industrial WLAN devices?
CVE-2021-33539 affects multiple versions of Weidmueller Industrial WLAN devices, allowing an attacker to bypass web authentication.
How can CVE-2021-33539 be fixed?
To fix CVE-2021-33539, users should apply the latest firmware update provided by Weidmueller.
Where can I find more information about CVE-2021-33539?
More information about CVE-2021-33539 can be found on the VDE CERT website: https://cert.vde.com/en-us/advisories/vde-2021-026