PT-2021-19458 · Chiyu Technology · Bf-630+4
Published
2021-06-01
·
Updated
2021-06-08
·
CVE-2021-31642
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
CHIYU Technology BIOSENSE (affected versions not specified)
CHIYU Technology Webpass (affected versions not specified)
CHIYU Technology BF-630 (affected versions not specified)
CHIYU Technology BF-631 (affected versions not specified)
CHIYU Technology SEMAC (affected versions not specified)
Description
A denial of service condition exists after an integer overflow in several IoT devices. The issue can be exploited by sending an unexpected integer (> 32 bits) on the
page parameter, which will crash the web portal and make it unavailable until a reboot of the device.Recommendations
For CHIYU Technology BIOSENSE, consider restricting access to the web portal until a fix is available.
For CHIYU Technology Webpass, avoid using the
page parameter with unexpected integers until the issue is resolved.
For CHIYU Technology BF-630, temporarily disable the web portal to prevent exploitation.
For CHIYU Technology BF-631, restrict access to the web portal to minimize the risk of exploitation.
For CHIYU Technology SEMAC, consider disabling the web portal until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bf-630
Bf-631
Biosense
Semac
Webpass