PT-2022-9219 · Sealevel Systems · Seaconnect 370W

Francesco Benvenuto

+1

·

Published

2022-02-04

·

Updated

2022-07-29

·

CVE-2021-21965

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Sealevel Systems, Inc. SeaConnect 370W version 1.3.34
Description A denial of service issue exists in the SeaMax remote configuration functionality. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this issue.
Recommendations For version 1.3.34, consider restricting access to the SeaMax remote configuration functionality until a fix is available. As a temporary workaround, network traffic should be monitored for suspicious packets to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21965

Affected Products

Seaconnect 370W