#VU60347 Improper access control in SeaConnect 370W - CVE-2021-21965
Published: February 7, 2022
SeaConnect 370W
Sealevel Systems
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Modbus/SeaMAX Remote Configuration functionality within SeaMAX Ethernet API. A remote attacker can bypass implemented security restrictions and perform a denial of service (DoS) attack.