ZeroHour

CVE-2021-45427

PoC
CVSS 3.1
9.8 critical
EPSS
19%p97
Published
()
Modified
Description

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

Vendors
emerson
Products
xweb300d evo firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.