9.8
CVE-2021-37163
- EPSS 0.58%
- Veröffentlicht 02.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Swisslog-healthcare ≫ Hmi-3 Control Panel Firmware Version < 7.2.5.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.679 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.