CRITICAL · 9.8

CVE-2021-31251

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by s...

Vulnerability Description

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Chiyu-TechBf-430 Firmware-
Chiyu-TechBf-430-
Chiyu-TechBf-431 Firmware-
Chiyu-TechBf-431-
Chiyu-TechBf-450M Firmware-
Chiyu-TechBf-450M-
Chiyu-TechSemac S2 Firmware-
Chiyu-TechSemac S2-
Chiyu-TechSemac D1 Firmware-
Chiyu-TechSemac D1-
Chiyu-TechSemac D2 Firmware-
Chiyu-TechSemac D2-
Chiyu-TechSemac D4 Firmware-
Chiyu-TechSemac D4-
Chiyu-TechSemac S3V3 Firmware-
Chiyu-TechSemac S3V3-
Chiyu-TechSemac D2 N300 Firmware-
Chiyu-TechSemac D2 N300-
Chiyu-TechSemac S1 Osdp Firmware-
Chiyu-TechSemac S1 Osdp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-31251?

CVE-2021-31251 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by s...

How severe is CVE-2021-31251?

CVE-2021-31251 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-31251?

Check the references section above for vendor advisories and patch information. Affected products include: Chiyu-Tech Bf-430 Firmware, Chiyu-Tech Bf-430, Chiyu-Tech Bf-431 Firmware, Chiyu-Tech Bf-431, Chiyu-Tech Bf-450M Firmware.