CVE-2021-42540

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2021
Last modified:
28/10/2021

Description

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:emerson:wireless_1410_gateway_firmware:*:*:*:*:*:*:*:* 4.7.94 (excluding)
cpe:2.3:h:emerson:wireless_1410_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:emerson:wireless_1410d_gateway_firmware:*:*:*:*:*:*:*:* 4.7.94 (excluding)
cpe:2.3:h:emerson:wireless_1410d_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:emerson:wireless_1420_gateway_firmware:*:*:*:*:*:*:*:* 4.7.94 (excluding)
cpe:2.3:h:emerson:wireless_1420_gateway:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools