Vulnerabilities > Pepperl Fuchs > WHA GW F2D2 0 AS Z2 ETH Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-08-31 CVE-2021-33555 Path Traversal vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
network
low complexity
pepperl-fuchs CWE-22
5.0
2021-08-31 CVE-2021-34559 HTTP Request Smuggling vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.
network
low complexity
pepperl-fuchs CWE-444
5.3
2021-08-31 CVE-2021-34560 Insufficiently Protected Credentials vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled.
local
low complexity
pepperl-fuchs CWE-522
5.5
2021-08-31 CVE-2021-34561 Reliance on Reverse DNS Resolution for a Security-Critical Action vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions.
network
low complexity
pepperl-fuchs CWE-350
8.8
2021-08-31 CVE-2021-34562 Cross-site Scripting vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.
network
low complexity
pepperl-fuchs CWE-79
6.1
2021-08-31 CVE-2021-34563 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie.
local
low complexity
pepperl-fuchs CWE-1004
3.3
2021-08-31 CVE-2021-34564 Cleartext Storage of Sensitive Information in a Cookie vulnerability in Pepperl-Fuchs products
Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.
local
low complexity
pepperl-fuchs CWE-315
2.1
2021-08-31 CVE-2021-34565 Use of Hard-coded Credentials vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
network
low complexity
pepperl-fuchs CWE-798
critical
9.8