Vulnerabilities > Emerson > Wireless 1410D Gateway Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-22 | CVE-2021-38485 | Improper Input Validation vulnerability in Emerson products The affected product is vulnerable to improper input validation in the restore file. | 8.8 |
2021-10-22 | CVE-2021-42538 | Command Injection vulnerability in Emerson products The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. | 8.8 |
2021-10-22 | CVE-2021-42539 | Missing Authentication for Critical Function vulnerability in Emerson products The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change. | 8.8 |
2021-10-22 | CVE-2021-42540 | Write-what-where Condition vulnerability in Emerson products The affected product is vulnerable to a unsanitized extract folder for system configuration. | 8.8 |
2021-10-22 | CVE-2021-42542 | Path Traversal vulnerability in Emerson products The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. | 8.8 |