PT-2022-9221 · Unknown · Seaconnect 370W
Francesco Benvenuto
+1
·
Published
2022-04-14
·
Updated
2022-04-21
·
CVE-2021-21967
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SeaConnect 370W version 1.3.34
Description
An out-of-bounds write issue exists in the OTA update task functionality. A specially-crafted MQTT payload can cause denial of service. This can be triggered by an attacker performing a man-in-the-middle attack.
Recommendations
For SeaConnect 370W version 1.3.34, consider restricting access to the OTA update task functionality until a fix is available. As a temporary workaround, avoid using the MQTT protocol for updates to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaconnect 370W