CVE-2021-37471
Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH command-line.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- cradlepoint/ibr600c firmware · cradlepoint/ibr600 firmware · cradlepoint/ibr900 firmware
- Source
- cve@mitre.org
References
- https://cradlepoint.com/product/endpoints/ibr900/Product, Vendor Advisory
- https://securitybytes.me/posts/cve-2021-37471/Exploit, Third Party Advisory
- https://cradlepoint.com/product/endpoints/ibr900/Product, Vendor Advisory
- https://securitybytes.me/posts/cve-2021-37471/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.