HIGH
A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7
Published Aug 2, 2021
7.5
HIGHCVSS 3.1
EPSS 2.06%
Description
A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.
Affected products
No data.
AND
- < 7.2.5.7
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-23740 Advisory
- https://www.armis.com/PwnedPiper x_refsource_MISCBroken Link
- https://www.swisslog-healthcare.com x_refsource_MISCProduct
- https://www.swisslog-healthcare.com/-/media/swisslog-healthcare/documents/customer-service/armis-documents/cve-2021-37166-bulletin---gui-socket-denial-of-service.pdf?rev=05321b2af1064eb2a6d6e6bf77604c6b&hash=40A927FE1153AA980428C93B2EF7EB40 x_refsource_MISCVendor Advisory
- https://www.swisslog-healthcare.com/en-us/customer-care/security-information/cve-disclosures#:~:text=CVE%20Disclosures%20%20%20%20Vulnerability%20Name%20%2C%20%20CVE-2021-37164%20%204%20more%20rows%20 x_refsource_MISC
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 2, 2021
Updated Aug 4, 2024
Reserved Jul 21, 2021
Link CVE-2021-37166
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-23740 Assigner mitre
Published Aug 2, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2021-23740