VulnerabilityModified
CVE-2021-45916
The programming function of Shockwall system has an improper input validation vulnerability.
LOW 3.5EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
The programming function of Shockwall system has an improper input validation vulnerability. An authenticated attacker within the local area network can send malicious response to the server to disrupt the service partially.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- smr/shenwang endpoint protection security system
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-5432-b9074-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-5432-b9074-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.