CVE-2021-44564
Last modified
CVE-2021-44564 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. The attack exploits the unsecured communication channel used between the administration tool Easyconnect and the SYNC device (in the affected family of SYNC products).
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kalkitech | Sync241-M1 Firmware | <= 4.15.3 |
| Kalkitech | Sync241-M2 Firmware | <= 4.15.3 |
| Kalkitech | Sync241-M4 Firmware | <= 4.15.3 |
| Kalkitech | Sync261-M1 Firmware | <= 4.15.3 |
| Kalkitech | Sync2000-M1 Firmware | <= 4.15.3 |
| Kalkitech | Sync2000-M2 Firmware | <= 4.15.3 |
| Kalkitech | Sync2000-M4 Firmware | <= 4.15.3 |
| Kalkitech | Sync2101-M1 Firmware | <= 4.15.3 |
| Kalkitech | Sync2101-M2 Firmware | <= 4.15.3 |
| Kalkitech | Sync2101-M6 Firmware | <= 4.15.3 |
| Kalkitech | Sync2101-M7 Firmware | <= 4.15.3 |
| Kalkitech | Sync2101-M8 Firmware | <= 4.15.3 |
| Kalkitech | Sync2111-M2 Firmware | <= 4.15.3 |
| Kalkitech | Sync2111-M3 Firmware | <= 4.15.3 |
| Kalkitech | Sync3000-M1 Firmware | <= 4.15.3 |
| Kalkitech | Sync3000-M2 Firmware | <= 4.15.3 |
| Kalkitech | Sync3000-M3 Firmware | <= 4.15.3 |
| Kalkitech | Sync3000-M4 Firmware | <= 4.15.3 |
| Kalkitech | Sync3000-M12 Firmware | <= 4.15.3 |
| Kalkitech | Sync221-M1 Firmware | <= 4.15.3 |
References
- https://www.kalkitech.com/cybersecurity/Vendor Advisory
- https://www.kalkitech.com/cybersecurity/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44564?
How severe is CVE-2021-44564?
How do I fix CVE-2021-44564?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-4455The Wordpress Plugin Smart Product Review plugin for WordPre…9.8
- CVE-2021-44550An Incorrect Access Control vulnerability exists in CoreNLP …9.8
- CVE-2021-44554Thinfinity VirtualUI before 3.0 allows a malicious actor to …5.3
- CVE-2021-44556National Library of the Netherlands digger < 6697d1269d981e3…9.1
- CVE-2021-44557National Library of the Netherlands multiNER <= c0440948057a…9.1
- CVE-2021-4456Net::CIDR versions before 0.24 for Perl mishandle leading ze…6.5
- CVE-2021-44565A Cross Site Scripting (XSS) vulnerability exists in Rosario…5.4
- CVE-2021-44566A Cross Site Scripting (XSS) vulnerability exists in Rosario…5.4
- CVE-2021-44567An unauthenticated SQL Injection vulnerability exists in Ros…9.8
- CVE-2021-44568Two heap-overflow vulnerabilities exist in openSUSE/libsolv …6.5
- CVE-2021-44569Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-4457The ZoomSounds plugin before 6.05 contains a PHP file allowi…9.1
Are you affected by CVE-2021-44564?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
