Lucene search

K
cveMitreCVE-2021-40856
HistoryDec 13, 2021 - 4:15 a.m.

CVE-2021-40856

2021-12-1304:15:06
CWE-706
mitre
web.nvd.nist.gov
51
cve-2021-40856
auerswald
comfortel
ip devices
authentication bypass
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.251

Percentile

96.8%

Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/…/ substring.

Affected configurations

Nvd
Node
auerswaldcomfortel_3600_ip_firmwareRange2.8f
AND
auerswaldcomfortel_3600_ipMatch-
Node
auerswaldcomfortel_2600_ip_firmwareRange2.8f
AND
auerswaldcomfortel_2600_ipMatch-
Node
auerswaldcomfortel_1400_ip_firmwareRange2.8f
AND
auerswaldcomfortel_1400_ipMatch-
VendorProductVersionCPE
auerswaldcomfortel_3600_ip_firmware*cpe:2.3:o:auerswald:comfortel_3600_ip_firmware:*:*:*:*:*:*:*:*
auerswaldcomfortel_3600_ip-cpe:2.3:h:auerswald:comfortel_3600_ip:-:*:*:*:*:*:*:*
auerswaldcomfortel_2600_ip_firmware*cpe:2.3:o:auerswald:comfortel_2600_ip_firmware:*:*:*:*:*:*:*:*
auerswaldcomfortel_2600_ip-cpe:2.3:h:auerswald:comfortel_2600_ip:-:*:*:*:*:*:*:*
auerswaldcomfortel_1400_ip_firmware*cpe:2.3:o:auerswald:comfortel_1400_ip_firmware:*:*:*:*:*:*:*:*
auerswaldcomfortel_1400_ip-cpe:2.3:h:auerswald:comfortel_1400_ip:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.251

Percentile

96.8%