PT-2021-7516 · Lantronix+1 · Lantronix Premierwave 2050+1
Matt Wiseman
·
Published
2021-12-22
·
Updated
2022-04-28
·
CVE-2021-21887
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lantronix PremierWave 2050 version 8.9.0.0R4
Hirschmann BAT-C2 (affected versions not specified)
Description
A stack-based buffer overflow issue exists in the Web Manager SslGenerateCSR functionality, allowing remote code execution through a specially crafted HTTP request. An attacker can trigger this issue by making an authenticated HTTP request.
Recommendations
For Lantronix PremierWave 2050 version 8.9.0.0R4, consider disabling the SslGenerateCSR functionality until a patch is available.
For Hirschmann BAT-C2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hirschmann Bat-C2
Lantronix Premierwave 2050