2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2021-27444" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2022-05-16T18:15:08.110" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T05:57:59.987" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator."
} ,
{
"lang" : "es" ,
"value" : "La l\u00ednea de productos Weintek cMT es vulnerable a varios controles de acceso inapropiados, que pueden permitir a un atacante no autenticado acceder y descargar remotamente informaci\u00f3n confidencial y llevar a cabo acciones administrativas en nombre de un administrador leg\u00edtimo"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-12-08 03:06:42 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-284"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "NVD-CWE-Other"
2023-04-24 12:24:31 +02:00
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-svr-100_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210305" ,
"matchCriteriaId" : "2BD9FCBF-CD84-4863-A4E4-613BD228D2CA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-svr-100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "408166F7-5030-4FDA-94CF-4DD2237A1EA7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-svr-102_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210305" ,
"matchCriteriaId" : "E6D1FD50-6AD9-4F6F-84A2-1646542350CC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-svr-102:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5EE3CBE0-6B56-4405-91E2-15DB0C6E7967"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-svr-200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210305" ,
"matchCriteriaId" : "176DF351-ECB2-44F8-9009-48B76D9EB867"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-svr-200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "673841CB-C2D6-486C-8C5D-0180173196D9"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-svr-202_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210305" ,
"matchCriteriaId" : "A7AA6AD2-B144-437E-B185-4BD47703A54B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-svr-202:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AB57299A-5F53-44A5-B1D3-2E554180562B"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-g01_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210209" ,
"matchCriteriaId" : "5985D77C-E9BF-4E1B-8128-A0737281B8FA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-g01:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E0ADA01D-E62C-4D53-B70D-BFB750CA2B52"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-g02_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210209" ,
"matchCriteriaId" : "0BF566CC-966E-48E9-B6C9-F6CA52FFEAA1"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-g02:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1FB93C5F-4C71-4337-B72F-FE9B6E5CF83C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-g03_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210222" ,
"matchCriteriaId" : "F59201D7-3D0B-446F-90B9-FD19C9DB04C0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-g03:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "61343FB6-5943-4FE7-9E3C-56F184622B7B"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-g04_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210222" ,
"matchCriteriaId" : "F264AD39-4A3F-4273-A951-6DCB6768E82F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-g04:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B2BCB236-F9AC-4729-BCAF-F005250C0F2E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt3071_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210218" ,
"matchCriteriaId" : "37D305D8-34F6-4BEF-99D4-CF4A18EFA9D3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt3071:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A4DE53C8-09D5-4D5E-97EE-A89E1478CD65"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt3072_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210218" ,
"matchCriteriaId" : "8A20906F-F91F-486A-9340-8D22C93C19AE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt3072:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E3F83A8D-1489-48AA-911B-5BA561A57896"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt3090_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210218" ,
"matchCriteriaId" : "A84ABF9C-EC9B-4CBF-967F-5F38DCD32A16"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt3090:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "79C1F694-08A2-46E7-95C2-8DFA3D64423B"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt3103_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210218" ,
"matchCriteriaId" : "B70E20F8-83E0-45C9-B02F-D1957AD47C6A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt3103:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F607716E-7B7B-4620-819C-F44341B8C37F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt3151_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210218" ,
"matchCriteriaId" : "F5065F83-0BD0-44B1-9E64-8689F0F3B4D0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt3151:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9FF5326B-5E33-4C11-9AC6-A90357078FCA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-hdm_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210204" ,
"matchCriteriaId" : "0A793B51-28F7-4A17-BD4C-74C2FCA053FC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-hdm:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E08E3518-A03F-486D-B67A-013F67026D78"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-fhd_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210208" ,
"matchCriteriaId" : "81DBEE28-6A04-43E0-9C5E-592162179896"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-fhd:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A132B170-A1FC-4D38-9965-0FF47B944FD5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:weintek:cmt-ctrl01_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "20210302" ,
"matchCriteriaId" : "38F4698D-B9D6-42E4-9867-9BDCC2F2F2A8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:weintek:cmt-ctrl01:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1C9CB899-1EE6-4599-861D-9BBA4856E5CE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://dl.weintek.com/public/Document/TEC/TEC21001E_cMT_EasyWeb_V1_Security_Issues.pdf" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://dl.weintek.com/public/Document/TEC/TEC21001E_cMT_EasyWeb_V1_Security_Issues.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://www.cisa.gov/uscert/ics/advisories/icsa-21-082-01" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
2023-04-24 12:24:31 +02:00
}
]
}