PT-2021-22126 · Trane · Symbio+2

Published

2021-11-22

·

Updated

2022-05-10

·

CVE-2021-38448

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue arises from the affected controllers not properly sanitizing the input containing code syntax. This allows an attacker to craft code that can alter the intended controller flow of the software.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38448

Affected Products

Symbio
Symbio 700
Symbio 800