CVE-2021-37166
Last modified
CVE-2021-37166 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Swisslog-Healthcare | Hmi-3 Control Panel Firmware | < 7.2.5.7 |
References
- https://www.armis.com/PwnedPiperBroken Link
- https://www.armis.com/PwnedPiperBroken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37166?
How severe is CVE-2021-37166?
How do I fix CVE-2021-37166?
Are you affected by CVE-2021-37166?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
