← back
CVE-2021-21971

CVE-2021-21971

CVSS 3.7 LOWEPSS 0.7%CWE-787
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.7EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
04 Feb 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
n/a · Sealevel