VDB
CVE-2021-33555
CVE-2021-33555
PUBLISHED
CVSS 7.5 HIGH
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
EPSS 0.90% · 76.0th percentile
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.90%
76.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pepperl-fuchs | wha-gw-f2d2-0-as-z2-eth_firmware | 0 |
| Phoenix Contact | WHA-GW-F2D2-0-AS- Z2-ETH.EIP | 3.0.7 |
| pepperl-fuchs | wha-gw-f2d2-0-as-_z2-eth.eip_firmware | 0 |
| Phoenix Contact | WHA-GW-F2D2-0-AS- Z2-ETH | 3.0.7 |
Timeline
- Aug 31, 2021 CVE Published
- Sep 1, 2021 EPSS Score
- Oct 29, 2021 EPSS Score
- Dec 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 22, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 21, 2022 EPSS Score
- Jun 17, 2022 EPSS Score
- Oct 12, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Feb 5, 2023 EPSS Score