Lucene search

K
cveTR-CERTCVE-2021-4105
HistoryFeb 24, 2023 - 12:15 p.m.

CVE-2021-4105

2023-02-2412:15:30
CWE-755
TR-CERT
web.nvd.nist.gov
27
cve-2021-4105
improper handling
parameters vulnerability
bg-tek
coslat firewall
remote code inclusion
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

60.8%

Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion.This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.

Affected configurations

Nvd
Node
bg-tekcoslat_bx5s1d3_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_bx5s1d3Match-
Node
bg-tekcoslat_bx5s1d4_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_bx5s1d4Match-
Node
bg-tekcoslat_bx5s1d5_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_bx5s1d5Match-
Node
bg-tekcoslat_rm1ds1000_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_rm1ds1000Match-
Node
bg-tekcoslat_rm2ds2000_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_rm2ds2000Match-
Node
bg-tekcoslat_rm2s200_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_rm2s200Match-
Node
bg-tekcoslat_rm3s300_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_rm3s300Match-
Node
bg-tekcoslat_rm4s500_firmwareRange5.24.0.r.201806305.24.0.r.20210727
AND
bg-tekcoslat_rm4s500Match-
VendorProductVersionCPE
bg-tekcoslat_bx5s1d3_firmware*cpe:2.3:o:bg-tek:coslat_bx5s1d3_firmware:*:*:*:*:*:*:*:*
bg-tekcoslat_bx5s1d3-cpe:2.3:h:bg-tek:coslat_bx5s1d3:-:*:*:*:*:*:*:*
bg-tekcoslat_bx5s1d4_firmware*cpe:2.3:o:bg-tek:coslat_bx5s1d4_firmware:*:*:*:*:*:*:*:*
bg-tekcoslat_bx5s1d4-cpe:2.3:h:bg-tek:coslat_bx5s1d4:-:*:*:*:*:*:*:*
bg-tekcoslat_bx5s1d5_firmware*cpe:2.3:o:bg-tek:coslat_bx5s1d5_firmware:*:*:*:*:*:*:*:*
bg-tekcoslat_bx5s1d5-cpe:2.3:h:bg-tek:coslat_bx5s1d5:-:*:*:*:*:*:*:*
bg-tekcoslat_rm1ds1000_firmware*cpe:2.3:o:bg-tek:coslat_rm1ds1000_firmware:*:*:*:*:*:*:*:*
bg-tekcoslat_rm1ds1000-cpe:2.3:h:bg-tek:coslat_rm1ds1000:-:*:*:*:*:*:*:*
bg-tekcoslat_rm2ds2000_firmware*cpe:2.3:o:bg-tek:coslat_rm2ds2000_firmware:*:*:*:*:*:*:*:*
bg-tekcoslat_rm2ds2000-cpe:2.3:h:bg-tek:coslat_rm2ds2000:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "COSLAT Firewall",
    "vendor": "BG-TEK",
    "versions": [
      {
        "lessThan": "5.24.0.r.20210727",
        "status": "affected",
        "version": "5.24.0.r.20180630",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

60.8%

Related for CVE-2021-4105