Lucene search

K
cvelistTalosCVELIST:CVE-2021-21889
HistoryDec 22, 2021 - 6:06 p.m.

CVE-2021-21889

2021-12-2218:06:38
CWE-121
talos
www.cve.org
3
buffer overflow
lantronix premierwave 2050
remote code execution
http request vulnerability

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.002

Percentile

53.4%

A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CNA Affected

[
  {
    "product": "Lantronix",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)"
      }
    ]
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.002

Percentile

53.4%

Related for CVELIST:CVE-2021-21889