First published: Mon Feb 14 2022(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Dixell Xweb-500 Firmware | ||
Emerson Dixell XWEB-500 | ||
All of | ||
Emerson Dixell XWEB-500 | ||
Emerson Dixell Xweb-500 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45420 is an arbitrary file write vulnerability affecting Emerson Dixell XWEB-500 products.
CVE-2021-45420 has a severity rating of 9.8 (critical).
Emerson Dixell XWEB-500 firmware is affected by CVE-2021-45420.
An attacker can exploit CVE-2021-45420 to write any file on the target system without authentication.
Yes, you can find more information about CVE-2021-45420 on the following websites: Dixell (dixell.com), Emerson (emerson.com), and Swascan (swascan.com).