CVE-2021-27459

EUVD-2021-14213
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
emersonx-stream_enhanced_xegp_firmware
*
emersonx-stream_enhanced_xegk_firmware
*
emersonx-stream_enhanced_xefd_firmware
*
emersonx-stream_enhanced_xexf_firmware
*
𝑥
= Vulnerable software versions