10

CVE-2021-27446

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WeintekCmt-svr-100 Firmware Version < 20210305
   WeintekCmt-svr-100 Version-
WeintekCmt-svr-102 Firmware Version < 20210305
   WeintekCmt-svr-102 Version-
WeintekCmt-svr-200 Firmware Version < 20210305
   WeintekCmt-svr-200 Version-
WeintekCmt-svr-202 Firmware Version < 20210305
   WeintekCmt-svr-202 Version-
WeintekCmt-g01 Firmware Version < 20210209
   WeintekCmt-g01 Version-
WeintekCmt-g02 Firmware Version < 20210209
   WeintekCmt-g02 Version-
WeintekCmt-g03 Firmware Version < 20210222
   WeintekCmt-g03 Version-
WeintekCmt-g04 Firmware Version < 20210222
   WeintekCmt-g04 Version-
WeintekCmt3071 Firmware Version < 20210218
   WeintekCmt3071 Version-
WeintekCmt3072 Firmware Version < 20210218
   WeintekCmt3072 Version-
WeintekCmt3090 Firmware Version < 20210218
   WeintekCmt3090 Version-
WeintekCmt3103 Firmware Version < 20210218
   WeintekCmt3103 Version-
WeintekCmt3151 Firmware Version < 20210218
   WeintekCmt3151 Version-
WeintekCmt-hdm Firmware Version < 20210204
   WeintekCmt-hdm Version-
WeintekCmt-fhd Firmware Version < 20210208
   WeintekCmt-fhd Version-
WeintekCmt-ctrl01 Firmware Version < 20210302
   WeintekCmt-ctrl01 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.511
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
ics-cert@hq.dhs.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.