CVE-2021-31251

CRITICALCVSS 9.8/10EPSS 35.71%

Last modified

CVE-2021-31251 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.. EPSS estimates a 35.71% chance of exploitation in the next 30 days.

Description

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
35.71%

98.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Chiyu-TechBf-430 FirmwareAll versions
Chiyu-TechBf-431 FirmwareAll versions
Chiyu-TechBf-450m FirmwareAll versions
Chiyu-TechSemac S2 FirmwareAll versions
Chiyu-TechSemac D1 FirmwareAll versions
Chiyu-TechSemac D2 FirmwareAll versions
Chiyu-TechSemac D4 FirmwareAll versions
Chiyu-TechSemac S3v3 FirmwareAll versions
Chiyu-TechSemac D2 N300 FirmwareAll versions
Chiyu-TechSemac S1 Osdp FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-31251?
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.
How severe is CVE-2021-31251?
CVE-2021-31251 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 35.71% probability of exploitation in the next 30 days.
How do I fix CVE-2021-31251?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-31251?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST