CVE-2021-34561

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2021-027 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip:-:*:*:*:*:*:*:*

History

29 Sep 2022, 15:24

Type Values Removed Values Added
First Time Pepperl-fuchs wha-gw-f2d2-0-as-z2-eth.eip Firmware
Pepperl-fuchs wha-gw-f2d2-0-as-z2-eth.eip
CPE cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-_z2-eth.eip:-:*:*:*:*:*:*:*
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-_z2-eth.eip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip:-:*:*:*:*:*:*:*
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth.eip_firmware:*:*:*:*:*:*:*:*

08 Sep 2021, 15:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 8.8
References (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2021-027 - (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2021-027 - Third Party Advisory
CPE cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-_z2-eth.eip:-:*:*:*:*:*:*:*
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pepperl-fuchs:wha-gw-f2d2-0-as-z2-eth:-:*:*:*:*:*:*:*
cpe:2.3:o:pepperl-fuchs:wha-gw-f2d2-0-as-_z2-eth.eip_firmware:*:*:*:*:*:*:*:*

31 Aug 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-31 11:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-34561

Mitre link : CVE-2021-34561

CVE.ORG link : CVE-2021-34561


JSON object : View

Products Affected

pepperl-fuchs

  • wha-gw-f2d2-0-as-z2-eth.eip_firmware
  • wha-gw-f2d2-0-as-z2-eth.eip
  • wha-gw-f2d2-0-as-z2-eth_firmware
  • wha-gw-f2d2-0-as-z2-eth
CWE
CWE-350

Reliance on Reverse DNS Resolution for a Security-Critical Action