CVE-2021-20993

EUVD-2021-8402
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CERTVDECNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
wago0852-0303_firmware
𝑥
≤ 1.2.3.s0
wago0852-1305_firmware
𝑥
≤ 1.1.7.s0
wago0852-1505_firmware
𝑥
≤ 1.1.6.s0
wago0852-1305\/000-001_firmware
𝑥
≤ 1.0.4.s0
wago0852-1505\/000-001_firmware
𝑥
≤ 1.0.4.s0
𝑥
= Vulnerable software versions