Code Injection in Symbio 800 and Symbio 700 - CVE-2021-38448

 

Code Injection in Symbio 800 and Symbio 700 - CVE-2021-38448

Published: September 27, 2021


Vulnerability identifier: #VU56880
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38448
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. An attacker with physical access can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Symbio 800
Symbio 700

How to mitigate CVE-2021-38448

Install updates from vendor's website.

Symbio 800 - update to 1.00.0007
Symbio 700 - update to 1.00.0023

External References

Related Security Bulletins