7.1

CVE-2021-34087

In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ultimaker ≫ Ultimaker S3 Firmware Version <= 6.3
   Ultimaker ≫ Ultimaker S3 Version -
Ultimaker ≫ Ultimaker S5 Firmware Version <= 6.3
   Ultimaker ≫ Ultimaker S5 Version -
Ultimaker ≫ Ultimaker 3 Firmware Version <= 5.2.16
   Ultimaker ≫ Ultimaker 3 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.522
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 2.8 3.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-1021 Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf
Third Party Advisory
Technical Description
https://ultimaker.com/3d-printers/ultimaker-s3
Vendor Advisory
Product
https://ultimaker.com/3d-printers/ultimaker-s5
Vendor Advisory
Product