Lucene search

K
cve[email protected]CVE-2021-35978
HistoryDec 10, 2021 - 1:15 p.m.

CVE-2021-35978

2021-12-1013:15:07
CWE-77
web.nvd.nist.gov
17
cve-2021-35978
digi transport
zing protocol
arbitrary code execution
remote command execution
firmware vulnerability
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.4%

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

Affected configurations

NVD
Node
digitransport_dr64_firmwareRange5.2.4.9
AND
digitransport_dr64Match-
Node
digitransport_sr44Match-
AND
digitransport_sr44_firmware
Node
digitransport_vc74Match-
AND
digitransport_vc74_firmwareRange5.2.4.9
Node
digitransport_wr11Match-
AND
digitransport_wr11_firmwareRange8.2.1.3
Node
digitransport_wr11_xtMatch-
AND
digitransport_wr11_xt_firmwareRange8.2.1.3
Node
digitransport_wr21Match-
AND
digitransport_wr21_firmwareRange8.2.1.3
Node
digitransport_wr31Match-
AND
digitransport_wr31_firmwareRange8.2.1.3
Node
digitransport_wr41Match-
AND
digitransport_wr41_firmwareRange5.0.0.05.2.4.6
OR
digitransport_wr41_firmwareRange6.0.0.06.1.3.5
OR
digitransport_wr41_firmwareRange8.0.0.08.3.1.2
Node
digitransport_wr44Matchv2
AND
digitransport_wr44_firmwareRange8.3.1.2

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.4%

Related for CVE-2021-35978