Improper Authorization in AIS-BW50-00 - CVE-2021-37101

 

Improper Authorization in AIS-BW50-00 - CVE-2021-37101

Published: September 9, 2021


Vulnerability identifier: #VU56418
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37101
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authorization checks.

The vulnerability exists due to improper authorization mangement. An attacker with physical access can bypass authorization checks and execute arbitrary code om the target system.


Affected software

AIS-BW50-00

How to mitigate CVE-2021-37101

Install updates from vendor's website.

AIS-BW50-00 - update to 9.0.6.3(H100SP11C00)

External References

Related Security Bulletins