Improper Verification of Cryptographic Signature in iManager NetEco 6000 and iManager NetEco - CVE-2021-37127
Published: October 21, 2021
Vulnerability identifier: #VU57586
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37127
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to a signature management issue. A remote administrator can forge signature, bypass the signature check to gain the admin privilege and access the device.
Affected software
iManager NetEco 6000
iManager NetEco
iManager NetEco
How to mitigate CVE-2021-37127
Install updates from vendor's website.
iManager NetEco 6000 - update to V600R009C00CP2401
iManager NetEco - update to V600R010C00SPC310
iManager NetEco - update to V600R010C00SPC310