PT-2022-9218 · Unknown · Seaconnect 370W

Francesco Benvenuto

+1

·

Published

2022-02-04

·

Updated

2022-10-25

·

CVE-2021-21964

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions SeaConnect 370W version 1.3.34
Description A denial of service issue exists in the Modbus configuration functionality. Specially-crafted network packets can cause a denial of service. An attacker can send a malicious packet to trigger this issue.
Recommendations For SeaConnect 370W version 1.3.34, consider restricting access to the Modbus configuration functionality until a fix is available. As a temporary workaround, implement network packet filtering to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-21964

Affected Products

Seaconnect 370W