PT-2021-17747 · Drager · Draeger X-Dock Firmware

Published

2021-05-20

·

Updated

2021-05-25

·

CVE-2021-28111

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Draeger X-Dock Firmware versions prior to 03.00.13
Description: The issue concerns hard-coded credentials in the firmware, which can be exploited by an authenticated attacker to achieve remote code execution.
Recommendations: For versions prior to 03.00.13, update the firmware to version 03.00.13 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28111
ZDI-21-604

Affected Products

Draeger X-Dock Firmware