Lucene search

K
nvd[email protected]NVD:CVE-2021-31251
HistoryJun 04, 2021 - 9:15 p.m.

CVE-2021-31251

2021-06-0421:15:07
CWE-287
web.nvd.nist.gov
4
authentication bypass
telnet server
vulnerability
privileged connection
target device

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.07

Percentile

94.1%

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

Affected configurations

Nvd
Node
chiyu-techbf-430_firmwareMatch-
AND
chiyu-techbf-430Match-
Node
chiyu-techbf-431_firmwareMatch-
AND
chiyu-techbf-431Match-
Node
chiyu-techbf-450m_firmwareMatch-
AND
chiyu-techbf-450mMatch-
Node
chiyu-techsemac_s2Match-
AND
chiyu-techsemac_s2_firmwareMatch-
Node
chiyu-techsemac_d1Match-
AND
chiyu-techsemac_d1_firmwareMatch-
Node
chiyu-techsemac_d2Match-
AND
chiyu-techsemac_d2_firmwareMatch-
Node
chiyu-techsemac_d4Match-
AND
chiyu-techsemac_d4_firmwareMatch-
Node
chiyu-techsemac_s3v3Match-
AND
chiyu-techsemac_s3v3_firmwareMatch-
Node
chiyu-techsemac_d2_n300Match-
AND
chiyu-techsemac_d2_n300_firmwareMatch-
Node
chiyu-techsemac_s1_osdpMatch-
AND
chiyu-techsemac_s1_osdp_firmwareMatch-
VendorProductVersionCPE
chiyu-techbf-430_firmware-cpe:2.3:o:chiyu-tech:bf-430_firmware:-:*:*:*:*:*:*:*
chiyu-techbf-430-cpe:2.3:h:chiyu-tech:bf-430:-:*:*:*:*:*:*:*
chiyu-techbf-431_firmware-cpe:2.3:o:chiyu-tech:bf-431_firmware:-:*:*:*:*:*:*:*
chiyu-techbf-431-cpe:2.3:h:chiyu-tech:bf-431:-:*:*:*:*:*:*:*
chiyu-techbf-450m_firmware-cpe:2.3:o:chiyu-tech:bf-450m_firmware:-:*:*:*:*:*:*:*
chiyu-techbf-450m-cpe:2.3:h:chiyu-tech:bf-450m:-:*:*:*:*:*:*:*
chiyu-techsemac_s2-cpe:2.3:h:chiyu-tech:semac_s2:-:*:*:*:*:*:*:*
chiyu-techsemac_s2_firmware-cpe:2.3:o:chiyu-tech:semac_s2_firmware:-:*:*:*:*:*:*:*
chiyu-techsemac_d1-cpe:2.3:h:chiyu-tech:semac_d1:-:*:*:*:*:*:*:*
chiyu-techsemac_d1_firmware-cpe:2.3:o:chiyu-tech:semac_d1_firmware:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.07

Percentile

94.1%