Lucene search

K
cveMitreCVE-2021-40859
HistoryDec 07, 2021 - 7:15 p.m.

CVE-2021-40859

2021-12-0719:15:07
mitre
web.nvd.nist.gov
57
cve-2021-40859
backdoors
auerswald
compact 5500r
web management
administrative access
device security

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.033

Percentile

91.4%

Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

Affected configurations

Nvd
Node
auerswaldcompact_5500r_firmwareMatch7.8abuild002
AND
auerswaldcompact_5500rMatch-
Node
auerswaldcompact_5500r_firmwareMatch8.0bbuild000
AND
auerswaldcompact_5500rMatch-
VendorProductVersionCPE
auerswaldcompact_5500r_firmware7.8acpe:2.3:o:auerswald:compact_5500r_firmware:7.8a:build002:*:*:*:*:*:*
auerswaldcompact_5500r-cpe:2.3:h:auerswald:compact_5500r:-:*:*:*:*:*:*:*
auerswaldcompact_5500r_firmware8.0bcpe:2.3:o:auerswald:compact_5500r_firmware:8.0b:build000:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.033

Percentile

91.4%