PT-2021-21547 · Swisslog · Swisslog Healthcare Nexus Panel

Published

2021-08-02

·

Updated

2023-08-08

·

CVE-2021-37167

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Swisslog Healthcare Nexus Panel versions prior to 7.2.5.7
Description An insecure permissions issue was discovered in the HMI3 Control Panel of the Swisslog Healthcare Nexus Panel. This issue allows a user logged in using the default credentials to gain root access to the device, providing permissions for all of the device's functionality.
Recommendations For versions prior to 7.2.5.7, update to version 7.2.5.7 or later to resolve the issue. As a temporary workaround, consider changing the default credentials to prevent unauthorized access. Restrict access to the device until the update can be applied to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-37167

Affected Products

Swisslog Healthcare Nexus Panel