6.8

CVE-2021-31642

Exploit
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chiyu-techSemac S2 Firmware Version-
   Chiyu-techSemac S2 Version-
Chiyu-techSemac D1 Firmware Version-
   Chiyu-techSemac D1 Version-
Chiyu-techSemac D2 Firmware Version-
   Chiyu-techSemac D2 Version-
Chiyu-techSemac D4 Firmware Version-
   Chiyu-techSemac D4 Version-
Chiyu-techSemac S3v3 Firmware Version-
   Chiyu-techSemac S3v3 Version-
Chiyu-techSemac D2 N300 Firmware Version-
   Chiyu-techSemac D2 N300 Version-
Chiyu-techSemac S1 Osdp Firmware Version-
   Chiyu-techSemac S1 Osdp Version-
Chiyu-techBf-631 Firmware Version-
   Chiyu-techBf-631 Version-
Chiyu-techBf-630 Firmware Version-
   Chiyu-techBf-630 Version-
Chiyu-techWebpass Firmware Version-
   Chiyu-techWebpass Version-
Chiyu-techBiosense Firmware Version-
   Chiyu-techBiosense Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 30.21% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.