#VU56880 Code Injection in Symbio 700 and Symbio 800 - CVE-2021-38448
Published: September 27, 2021
Symbio 700
Symbio 800
Trane
Description
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. An attacker with physical access can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.