CVE-2021-45427: Path Traversal
Published Dec 30, 2021
·Updated
Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.
Affected Software
4 affected components
Emerson Xweb300d Evo Firmware=3.0.7-3ee403
Emerson Xweb300d Evo
All of the following
Emerson Xweb300d Evo Firmware=3.0.7-3ee403
Emerson Xweb300d Evo
Event History
Dec 30, 2021
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45427?
CVE-2021-45427 has a severity rating of 9.8 (Critical).
2
What is the vulnerability in Emerson XWEB 300D EVO 3.0.7--3ee403?
The vulnerability in Emerson XWEB 300D EVO 3.0.7--3ee403 is unauthenticated arbitrary file deletion due to path traversal.
3
How does the vulnerability in Emerson XWEB 300D EVO 3.0.7--3ee403 occur?
The vulnerability occurs due to incorrect access control and directory traversal, allowing an attacker to browse and delete files without authentication.
4
Which software versions of Emerson XWEB 300D EVO are affected?
Emerson XWEB 300D EVO firmware version 3.0.7-3ee403 is affected.
5
Is the Emerson XWEB 300D EVO itself vulnerable to the CVE-2021-45427 vulnerability?
No, the Emerson XWEB 300D EVO itself is not vulnerable to CVE-2021-45427.