CVE-2021-45421: Infoleak
UNSUPPORTED WHEN ASSIGNED Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Emerson Dixell XWEB-500from your environment.Remove or replace the unsupported Emerson Dixell XWEB-500 product (not supported since 2018) to remediate information disclosure via directory listing.
- Compensating control
If XWEB-500 cannot be immediately removed/replaced, prevent external access to the exposed remote directories (e.g., use network restrictions/ACLs or other access controls) to mitigate directory-listing information disclosure.
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45421.
What products are affected by this vulnerability?
Emerson Dixell XWEB-500 products are affected by this vulnerability.
How does this vulnerability occur?
This vulnerability occurs due to information disclosure via directory listing in Emerson Dixell XWEB-500 products.
What is the severity of CVE-2021-45421?
The severity of CVE-2021-45421 is high with a CVSS score of 7.5.
Is there a fix available for this vulnerability?
No, there is no fix available for this vulnerability as the affected product, Emerson Dixell XWEB-500, has not been supported since 2018 and should be removed.