CVE-2021-44746

MEDIUMCVSS 5.3/10EPSS 1.07%

Last modified

CVE-2021-44746 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.

Description

UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
1.07%

60.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
NecUniverge Dt830 Firmware<= 5.2.7.0
NecUniverge Dt820 Firmware<= 3.2.7.0
NecUniverge Dt930 Firmware<= 2.4.0.0
NecUniverge Dt900 Data Maintenance Tool<= 5.3.0.0
NecUniverge Dt800 Data Maintenance Tool<= 4.2.0.0
NecUniverge Ip Phone Manager<= 8.9.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-44746?
UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.
How severe is CVE-2021-44746?
CVE-2021-44746 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.07% probability of exploitation in the next 30 days.
How do I fix CVE-2021-44746?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-44746?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST