SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26621

An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01.

CRITICAL 9.8EPSS 1.74%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this vulnerability by using the property that the target program copies parameter values to memory through the strcpy() function.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.74% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
netu/mex01 firmware
Source
vuln@krcert.or.kr

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.