CVE-2021-42542: Emerson WirelessHART Gateway
Published Oct 22, 2021
·Updated
The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.
Affected Software
15 affected componentsFixes available
Emerson Wireless 1410 Gateway Firmware<4.7.94
Emerson Wireless 1410 Gateway
Emerson Wireless 1410d Gateway Firmware<4.7.94
Emerson Wireless 1410d Gateway
Emerson Wireless 1420 Gateway Firmware<4.7.94
Emerson Wireless 1420 Gateway
All of the following
Emerson Wireless 1410 Gateway Firmware<4.7.94
Emerson Wireless 1410 Gateway
All of the following
Emerson Wireless 1410d Gateway Firmware<4.7.94
Emerson Wireless 1410d Gateway
All of the following
Emerson Wireless 1420 Gateway Firmware<4.7.94
Emerson Wireless 1420 Gateway
Emerson WirelessHART 1410 Gateway<4.7.94
4.7.94
Emerson WirelessHART 1410D Gateway<4.7.94
4.7.94
Emerson WirelessHART 1420 Gateway<4.7.94
4.7.94
Remediation
Patch Available
Information
Emerson recommends upgrading to v4.7.105 to address these vulnerabilities.
Users can visit the Emerson Gate Firmware site for and download instructions.
If affected users do not yet have a free Guardian account, please see the updated Emerson Gateway Firmware download process by following the link above and viewing the download guide.
Event History
Oct 22, 2021
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-42542?
The severity of CVE-2021-42542 is high with a severity value of 8.8.
2
Which products are affected by CVE-2021-42542?
The affected products are Emerson Wireless 1410 Gateway Firmware (up to exclusive version 4.7.94) and Emerson Wireless 1410d Gateway Firmware (up to exclusive version 4.7.94).
3
What is the vulnerability in CVE-2021-42542?
The vulnerability in CVE-2021-42542 is directory traversal due to mishandling of provided backup folder structure.
4
How can I fix CVE-2021-42542?
Apply the latest firmware update from Emerson to fix CVE-2021-42542.
5
Where can I find more information about CVE-2021-42542?
You can find more information about CVE-2021-42542 in the advisory provided by the US-CERT.