6.5
CVSSv3

CVE-2021-39243

Published: 23/08/2021 Updated: 26/08/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

altus nexto_nx3003_firmware 1.8.11.0

altus nexto_nx3004_firmware 1.8.11.0

altus nexto_nx3005_firmware 1.8.11.0

altus nexto_nx3010_firmware 1.8.3.0

altus nexto_nx3020_firmware 1.8.3.0

altus nexto_nx3030_firmware 1.8.3.0

altus nexto_nx5100_firmware 1.8.11.0

altus nexto_nx5101_firmware 1.8.11.0

altus nexto_nx5110_firmware 1.1.2.8

altus nexto_nx5210_firmware 1.1.2.8

altus nexto_xpress_xp300_firmware 1.8.11.0

altus nexto_xpress_xp315_firmware 1.8.11.0

altus nexto_xpress_xp325_firmware 1.8.11.0

altus nexto_xpress_xp340_firmware 1.8.11.0

altus hadron_xtorm_hx3040_firmware 1.7.58.0

Exploits

Multiple Altus Sistemas de Automacao products such as the Nexto NX30xx Series, Nexto NX5xxx Series, Nexto Xpress XP3xx Series, and Hadron Xtorm HX3040 Series suffer from command injection, cross site request forgery, and hardcoded credential vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20210819-0 :: Multiple critical vulnerabilities in Altus Nexto and Hadron series <!--X-Subject-Header-E ...