CVE-2021-41543
Last modified
CVE-2021-41543 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Climatix Pol909 Firmware | < 11.36 |
| Siemens | Climatix Pol909 Firmware | < 11.44 |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdfPatch, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41543?
How severe is CVE-2021-41543?
How do I fix CVE-2021-41543?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41538A vulnerability has been identified in NX 1953 Series (All v…3.3
- CVE-2021-41539A vulnerability has been identified in Solid Edge SE2021 (Al…7.8
- CVE-2021-4154A use-after-free flaw was found in cgroup1_parse_param in ke…8.8
- CVE-2021-41540A vulnerability has been identified in Solid Edge SE2021 (Al…7.8
- CVE-2021-41541A vulnerability has been identified in Climatix POL909 (AWB …6.1
- CVE-2021-41542A vulnerability has been identified in Climatix POL909 (AWB …6.1
- CVE-2021-41544A vulnerability has been identified in Siemens Software Cent…7.8
- CVE-2021-41545A vulnerability has been identified in Desigo DXR2 (All vers…7.5
- CVE-2021-41546A vulnerability has been identified in RUGGEDCOM ROX MX5000 …7.5
- CVE-2021-41547A vulnerability has been identified in Teamcenter Active Wor…7.2
- CVE-2021-4155A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL …5.5
- CVE-2021-41550Leostream Connection Broker 9.0.40.17 allows administrator t…7.2
Are you affected by CVE-2021-41543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
