Lucene search

K
cve[email protected]CVE-2021-40422
HistoryApr 14, 2022 - 8:15 p.m.

CVE-2021-40422

2022-04-1420:15:08
CWE-798
CWE-330
web.nvd.nist.gov
42
cve-2021-40422
authentication bypass
remote code execution
swift sensors
network security

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

Affected configurations

Vulners
NVD
Node
swift_sensorsswift_sensors_gatewayRangeSG3-1010

CNA Affected

[
  {
    "vendor": "Swift Sensors",
    "product": "Swift Sensors Gateway",
    "versions": [
      {
        "version": "SG3-1010",
        "status": "affected"
      }
    ]
  }
]

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

Related for CVE-2021-40422