LiveActive security incident?Get immediate response
CVE Record

CVE-2021-20999: WEIDMUELLER: Accidentally open network port in u-controls and IoT-Gateways

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

CriticalCVSS 9.4Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

Some Weidmüller industrial controllers and IoT gateways expose a network port that was meant to be internal only. An unauthenticated network attacker may be able to manipulate the device or stop its operation, creating a serious operational availability and integrity risk.

Executive priority

Treat this as a high-priority OT exposure issue. It affects device integrity and availability, does not require authentication, and could interrupt operations if exposed. Prioritize discovery, network restriction, and vendor-guided remediation for reachable devices.

Technical view

CVE-2021-20999 is a CWE-668 exposure issue in Weidmüller u-controls and IoT-Gateways up to version 1.12.1. The port is reachable through external interfaces. The CVSS 3.1 score is 9.4, with network attack vector, low complexity, no privileges, no user interaction, and high integrity and availability impact.

Likely exposure

Exposure is most likely where affected UC20-WL2000-AC, UC20-WL2000-IOT, IOT-GW30, or IOT-GW30-4G-EU devices are reachable from corporate, partner, remote-access, or internet-adjacent networks. The source bundle lists versions 1.3.0, 1.10.0, and 1.11.0, and states versions up to 1.12.1 are affected.

Exploitation context

The provided sources do not state active exploitation, and the CVE is not marked KEV in the bundle. The risk is still high because exploitation is network-based, unauthenticated, low complexity, and could affect device operation in industrial or IoT environments.

Researcher notes

The bundle identifies the weakness as CWE-668 and provides CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. Evidence is sufficient for exposure and severity, but the bundle does not include exploit details, observed exploitation, or a specific fixed version statement beyond affected versions up to 1.12.1.

Mitigation direction

  • Identify affected Weidmüller devices and firmware versions in OT and remote-access networks.
  • Restrict network access to device services from untrusted or unnecessary segments.
  • Check Weidmüller and VDE guidance for fixed firmware or vendor-approved remediation.
  • Prioritize remediation for devices reachable across routed networks or remote access paths.
  • Monitor affected devices for unexpected configuration changes, faults, or stoppages.

Validation and detection

  • Confirm device model and firmware version against the affected product list.
  • Review firewall and segmentation rules for access to affected devices.
  • Verify whether any external interface exposes services not required for operations.
  • Check vendor advisories for current remediation status before changing production devices.
  • Document compensating controls where immediate firmware remediation is not possible.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-668: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-20999 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.4CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H3.95.5Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9.4Critical
CVSS 3.1 vector shape for CVE-2021-20999Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
WeidmüllerUC20-WL2000-AC (No. 1334950000)1.3.0, 1.10.0, 1.11.0Listed
WeidmüllerUC20-WL2000-IOT (No. 1334990000)1.3.0, 1.10.0, 1.11.0Listed
WeidmüllerIOT-GW30 (No. 2682620000)1.3.0, 1.10.0, 1.11.0Listed
WeidmüllerIOT-GW30-4G-EU (No. 2682630000)1.3.0, 1.10.0, 1.11.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-668 · source CWE mapping

Exposure of Resource to Wrong Sphere

Exposure of Resource to Wrong Sphere represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.