Lucene search

K
nvd[email protected]NVD:CVE-2021-27372
HistoryMar 25, 2021 - 10:15 p.m.

CVE-2021-27372

2021-03-2522:15:12
CWE-522
web.nvd.nist.gov
2
realtek xpon rtl9601d
sdk 1.9
plaintext password
vulnerability
network monitoring
arbitrary commands

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.5%

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.

Affected configurations

Nvd
Node
realtekxpon_rtl9601d_software_development_kitMatch1.9
AND
realtekxpon_rtl9601dMatch-
VendorProductVersionCPE
realtekxpon_rtl9601d_software_development_kit1.9cpe:2.3:a:realtek:xpon_rtl9601d_software_development_kit:1.9:*:*:*:*:*:*:*
realtekxpon_rtl9601d-cpe:2.3:h:realtek:xpon_rtl9601d:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.5%

Related for NVD:CVE-2021-27372