PT-2022-9221 · Unknown · Seaconnect 370W

Francesco Benvenuto

+1

·

Published

2022-04-14

·

Updated

2022-04-21

·

CVE-2021-21967

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SeaConnect 370W version 1.3.34
Description An out-of-bounds write issue exists in the OTA update task functionality. A specially-crafted MQTT payload can cause denial of service. This can be triggered by an attacker performing a man-in-the-middle attack.
Recommendations For SeaConnect 370W version 1.3.34, consider restricting access to the OTA update task functionality until a fix is available. As a temporary workaround, avoid using the MQTT protocol for updates to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21967

Affected Products

Seaconnect 370W