CVE-2021-42540: Emerson WirelessHART Gateway
The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2021-42540?
CVE-2021-42540 is a vulnerability where the affected product has an unsanitized extract folder for system configuration, allowing a low-privileged user to overwrite settings and key functionality.
What is the severity of CVE-2021-42540?
CVE-2021-42540 has a severity score of 8.8 (high).
Which software versions are affected by CVE-2021-42540?
Versions up to and excluding 4.7.94 of Emerson Wireless 1410 Gateway Firmware and Emerson Wireless 1410d Gateway Firmware are affected.
How can a low-privileged user exploit CVE-2021-42540?
A low-privileged user can exploit CVE-2021-42540 by leveraging the unsanitized extract folder for system configuration to overwrite settings and key functionality.
Where can I find more information about CVE-2021-42540?
You can find more information about CVE-2021-42540 in the advisory issued by the United States Computer Emergency Readiness Team (US-CERT).