CVE-2021-20999

CRITICAL

Weidmüller u-controls/IoT-Gateways <1.12.1 - DoS

Title source: llm

Description

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

Scores

CVSS v3 9.4
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Classification

CWE
CWE-668
Status published

Affected Products (12)

weidmueller/uc20-wl2000-ac_firmware < 1.9.1
weidmueller/uc20-wl2000-ac_firmware
weidmueller/uc20-wl2000-ac_firmware
weidmueller/uc20-wl2000-iot_firmware < 1.9.1
weidmueller/uc20-wl2000-iot_firmware
weidmueller/uc20-wl2000-iot_firmware
weidmueller/iot-gw30_firmware < 1.9.1
weidmueller/iot-gw30_firmware
weidmueller/iot-gw30_firmware
weidmueller/iot-gw30-4g-eu_firmware < 1.9.1
weidmueller/iot-gw30-4g-eu_firmware
weidmueller/iot-gw30-4g-eu_firmware

Timeline

Published May 13, 2021
Tracked Since Feb 18, 2026