5
CVSSv2

CVE-2021-39245

Published: 23/08/2021 Updated: 26/08/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

altus nexto nx3003 firmware 1.8.11.0

altus nexto nx3004 firmware 1.8.11.0

altus nexto nx3005 firmware 1.8.11.0

altus nexto nx3010 firmware 1.8.3.0

altus nexto nx3020 firmware 1.8.3.0

altus nexto nx3030 firmware 1.8.3.0

altus nexto nx5100 firmware 1.8.11.0

altus nexto nx5101 firmware 1.8.11.0

altus nexto nx5110 firmware 1.1.2.8

altus nexto nx5210 firmware 1.1.2.8

altus nexto xpress xp300 firmware 1.8.11.0

altus nexto xpress xp315 firmware 1.8.11.0

altus nexto xpress xp325 firmware 1.8.11.0

altus nexto xpress xp340 firmware 1.8.11.0

altus hadron xtorm hx3040 firmware 1.7.58.0

Exploits

Multiple Altus Sistemas de Automacao products such as the Nexto NX30xx Series, Nexto NX5xxx Series, Nexto Xpress XP3xx Series, and Hadron Xtorm HX3040 Series suffer from command injection, cross site request forgery, and hardcoded credential vulnerabilities ...

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory < 20210819-0 > ======================================================================= title: Multiple Critical Vulnerabilities product: Multiple Altus Sistemas de Automacao products: Nexto NX30xx Series Nexto NX5xxx Series ...