CRITICAL🇵🇱 Wersja polska

CVE-2021-45420

CVSS 9.8v3.1pub. 2022-02-14upd. 2026-07-09

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Emerson Dixell Xweb 500

    HW
    Emerson
    all versions
  • Emerson Dixell Xweb 500 Firmware

    OS
    Emerson
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References

Related vulnerabilities

CVE-2021-45421HIGH7.5same product

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential att...

CVE-2023-46687CRITICAL9.8PL ✓same vendor

Emerson Rosemount GC370XA/GC700XA/GC1500XA — zdalne RCE jako root bez uwierzytelnienia

CVE-2023-1935CRITICAL9.4PL ✓same vendor

Authentication bypass w urządzeniach Emerson ROC800-Series RTU

CVE-2022-30264CRITICAL9.8PL ✓same vendor

Emerson ROC/FloBoss RTU — niezabezpieczone operacje na systemie plików przez ROC protocol

CVE-2020-10640CRITICAL10.0PL ✓same vendor

RCE z uprawnieniami systemowymi w Emerson OpenEnterprise SCADA Server