CVE-2021-38451 Information
Jun 07, 2022
cve
Description
The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes the user must supply parameters. There is no sanitation on the value of the offset which allows the client to specify any offset and read out-of-bounds data.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Reference
https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.7
Share on: