VYPR

SeaConnect 370W

by Sealevel Systems

CVEs (12)

  • CVE-2021-21961CriFeb 4, 2022
    risk 0.65cvss 10.0epss 0.03

    A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21960CriFeb 4, 2022
    risk 0.65cvss 10.0epss 0.03

    A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21965CriFeb 4, 2022
    risk 0.61cvss 9.3epss 0.01

    A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21968HigFeb 4, 2022
    risk 0.54cvss 8.3epss 0.01

    A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

  • CVE-2021-21970HigFeb 4, 2022
    risk 0.53cvss 8.1epss 0.01

    An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [3] the json_object_get_string to populate the p_name global variable. The p_name is only…

  • CVE-2021-21969HigFeb 4, 2022
    risk 0.53cvss 8.1epss 0.01

    An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload global variable. The p_payload is…

  • CVE-2021-21962HigFeb 4, 2022
    risk 0.53cvss 8.1epss 0.02

    A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in…

  • CVE-2021-21959HigFeb 4, 2022
    risk 0.53cvss 8.1epss 0.01

    A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

  • CVE-2021-21964HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21967MedApr 14, 2022
    risk 0.38cvss 5.9epss 0.01

    An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

  • CVE-2021-21971MedFeb 4, 2022
    risk 0.38cvss 5.9epss 0.01

    An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

  • CVE-2021-21963MedFeb 4, 2022
    risk 0.38cvss 5.9epss 0.00

    An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to…