PT-2022-9785 · Sihas · Gcm-300+2

Published

2022-06-22

·

Updated

2023-06-26

·

CVE-2021-26637

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiHAS's SGW-300 (affected versions not specified) SiHAS's ACM-300 (affected versions not specified) SiHAS's GCM-300 (affected versions not specified)
Description The issue is related to the lack of account authentication and permission check logic in the firmware and existing apps of the affected devices. This allows unauthorized users to remotely control the device.
Recommendations For SiHAS's SGW-300, consider implementing proper account authentication and permission check logic to prevent unauthorized access. For SiHAS's ACM-300, consider implementing proper account authentication and permission check logic to prevent unauthorized access. For SiHAS's GCM-300, consider implementing proper account authentication and permission check logic to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-26637

Affected Products

Acm-300
Gcm-300
Sgw-300