10

CVE-2021-42109

Exploit
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vitec ≫ Exterity Avediaserver Version <= 2021-04-30
Vitec ≫ Avediastream M9605 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream M9605 Version -
Vitec ≫ Avediastream M9400 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream M9400 Version -
Vitec ≫ Avediastream M9405 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream M9405 Version -
Vitec ≫ Avediastream M9305 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream M9305 Version -
Vitec ≫ Avediastream R9300 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream R9300 Version -
Vitec ≫ Avediastream R9310 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream R9310 Version -
Vitec ≫ Avediastream M9325 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream M9325 Version -
Vitec ≫ Avediastream R9350 Firmware Version <= 2021-04-30
   Vitec ≫ Avediastream R9350 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.66% 0.744
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

https://whitehoodhacker.net/posts/2021-10-04-the-big-rick
Third Party Advisory
Exploit
https://www.exterity.com
Vendor Advisory