CVE-2021-21001

EUVD-2021-8410
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CERTVDECNA
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
wago750-8202_firmware
𝑥
< 03.06.19_\(18\)
wago750-8203_firmware
𝑥
< 03.06.19_\(18\)
wago750-8204_firmware
𝑥
< 03.06.19_\(18\)
wago750-8206_firmware
𝑥
< 03.06.19_\(18\)
wago750-8207_firmware
𝑥
< 03.06.19_\(18\)
wago750-8208_firmware
𝑥
< 03.06.19_\(18\)
wago750-8210_firmware
𝑥
< 03.06.19_\(18\)
wago750-8211_firmware
𝑥
< 03.06.19_\(18\)
wago750-8212_firmware
𝑥
< 03.06.19_\(18\)
wago750-8213_firmware
𝑥
< 03.06.19_\(18\)
wago750-8214_firmware
𝑥
< 03.06.19_\(18\)
wago750-8216_firmware
𝑥
< 03.06.19_\(18\)
wago750-8217_firmware
𝑥
< 03.06.19_\(18\)
𝑥
= Vulnerable software versions