First published: Tue Oct 05 2021(Updated: )
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Wireless 1410 Gateway Firmware | <4.7.94 | |
Emerson Wireless 1410 Gateway | ||
Emerson Wireless 1410d Gateway Firmware | <4.7.94 | |
Emerson Wireless 1410d Gateway | ||
Emerson Wireless 1420 Gateway Firmware | <4.7.94 | |
Emerson Wireless 1420 Gateway | ||
Emerson WirelessHART 1410 Gateway | <4.7.94 | 4.7.94 |
Emerson WirelessHART 1410D Gateway | <4.7.94 | 4.7.94 |
Emerson WirelessHART 1420 Gateway | <4.7.94 | 4.7.94 |
All of | ||
Emerson Wireless 1410 Gateway Firmware | <4.7.94 | |
Emerson Wireless 1410 Gateway | ||
All of | ||
Emerson Wireless 1410d Gateway Firmware | <4.7.94 | |
Emerson Wireless 1410d Gateway | ||
All of | ||
Emerson Wireless 1420 Gateway Firmware | <4.7.94 | |
Emerson Wireless 1420 Gateway |
Emerson recommends upgrading to v4.7.105 to address these vulnerabilities. Users can visit the Emerson Gate Firmware site for and download instructions. If affected users do not yet have a free Guardian account, please see the updated Emerson Gateway Firmware download process by following the link above and viewing the download guide.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42536 is a vulnerability in Emerson Wireless 1410 and 1420 Gateway Firmware that allows all users to read global variables, leading to a disclosure of peer username and password.
The severity of CVE-2021-42536 is high with a CVSS score of 6.5.
Emerson Wireless 1410 Gateway Firmware versions up to and excluding 4.7.94 and Emerson Wireless 1420 Gateway Firmware versions up to and excluding 4.7.94 are affected by CVE-2021-42536.
CVE-2021-42536 allows all users to read global variables, which can lead to a disclosure of peer username and password.
You can find more information about CVE-2021-42536 on the US-CERT website at https://us-cert.cisa.gov/ics/advisories/icsa-21-278-02.