PT-2022-9219 · Sealevel Systems · Seaconnect 370W
Francesco Benvenuto
+1
·
Published
2022-02-04
·
Updated
2022-07-29
·
CVE-2021-21965
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Sealevel Systems, Inc. SeaConnect 370W version 1.3.34
Description
A denial of service issue exists in the SeaMax remote configuration functionality. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this issue.
Recommendations
For version 1.3.34, consider restricting access to the SeaMax remote configuration functionality until a fix is available. As a temporary workaround, network traffic should be monitored for suspicious packets to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Seaconnect 370W