Lucene search

K
cveMitreCVE-2021-27372
HistoryMar 25, 2021 - 10:15 p.m.

CVE-2021-27372

2021-03-2522:15:12
CWE-522
mitre
web.nvd.nist.gov
43
cve-2021-27372
realtek xpon
rtl9601d sdk 1.9
plaintext password
root access
network monitoring
arbitrary commands

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

77.5%

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.

Affected configurations

Nvd
Node
realtekxpon_rtl9601d_software_development_kitMatch1.9
AND
realtekxpon_rtl9601dMatch-
VendorProductVersionCPE
realtekxpon_rtl9601d_software_development_kit1.9cpe:2.3:a:realtek:xpon_rtl9601d_software_development_kit:1.9:*:*:*:*:*:*:*
realtekxpon_rtl9601d-cpe:2.3:h:realtek:xpon_rtl9601d:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

77.5%

Related for CVE-2021-27372