CVE-2021-34560: A vulnerability in WirelessHART-Gateway <= 3.0.9 could lead to information exposure of sensitive information
Published Aug 31, 2021
·Updated
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
Affected Software
4 affected components
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth Firmware<=3.0.9
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware<=3.0.9
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip
Remediation
Information
No update available.
Event History
Aug 31, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-34560.
2
What is the severity level of CVE-2021-34560?
The severity level of CVE-2021-34560 is medium (5.5).
3
What is the impact of CVE-2021-34560?
CVE-2021-34560 allows an attacker to capture stored credentials on a user's computer if they have control over it.
4
How can I fix CVE-2021-34560?
To fix CVE-2021-34560, update PEPPERL+FUCHS WirelessHART-Gateway to version 3.0.10 or higher to disable autocomplete on the password field.
5
Where can I find more information about CVE-2021-34560?
You can find more information about CVE-2021-34560 at the following reference: https://cert.vde.com/en-us/advisories/vde-2021-027