PT-2021-7516 · Lantronix+1 · Lantronix Premierwave 2050+1

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-04-28

·

CVE-2021-21887

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lantronix PremierWave 2050 version 8.9.0.0R4 Hirschmann BAT-C2 (affected versions not specified)
Description A stack-based buffer overflow issue exists in the Web Manager SslGenerateCSR functionality, allowing remote code execution through a specially crafted HTTP request. An attacker can trigger this issue by making an authenticated HTTP request.
Recommendations For Lantronix PremierWave 2050 version 8.9.0.0R4, consider disabling the SslGenerateCSR functionality until a patch is available. For Hirschmann BAT-C2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07106
CVE-2021-21887

Affected Products

Hirschmann Bat-C2
Lantronix Premierwave 2050