6.5
CVSSv2

CVE-2021-40857

Published: 13/12/2021 Updated: 31/03/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Auerswald COMpact 5500R devices prior to 8.2B allow Privilege Escalation via the passwd=1 substring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

auerswald compact_5500r_ip_firmware

auerswald compact_5200r_ip_firmware

auerswald compact_5000r_ip_firmware

auerswald compact_4000_ip_firmware

auerswald commander_6000r_ip_firmware

auerswald commander_6000rx_ip_firmware

auerswald commander_business\\(19\\\"\\)_ip_firmware

auerswald commander_basic.2\\(19\\\"\\)_ip_firmware

auerswald compact_5010_voip_ip_firmware

auerswald compact_5020_voip_ip_firmware

Exploits

RedTeam Pentesting discovered a vulnerability in the web-based management interface of the Auerswald COMpact 5500R PBX which allows low-privileged users to access passwords of administrative user accounts Affected versions include 80B and below ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [RT-SA-2021-005] Auerswald COMpact Privilege Escalation <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: R ...