peter bassill · operator
$ cve CVE-2021-45427 JSON

CVE-2021-45427

9.8
CRITICAL · CVSS 3.1 · EPSS 19.2% (pctl 97)

Patch early

EPSS 19.2% — above the 10% action threshold.

Description

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.19% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2021-12-30
Last modified2026-06-17

Affected (2)

VendorProduct
emersonxweb300d evo
emersonxweb300d evo firmware

References

→ the Explorer  ·  watch your stack  ·  NVD