Vulnerability Description
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chiyu-Tech | Semac S2 Firmware | - |
| Chiyu-Tech | Semac S2 | - |
| Chiyu-Tech | Semac D1 Firmware | - |
| Chiyu-Tech | Semac D1 | - |
| Chiyu-Tech | Semac D2 Firmware | - |
| Chiyu-Tech | Semac D2 | - |
| Chiyu-Tech | Semac D4 Firmware | - |
| Chiyu-Tech | Semac D4 | - |
| Chiyu-Tech | Semac S3V3 Firmware | - |
| Chiyu-Tech | Semac S3V3 | - |
| Chiyu-Tech | Semac D2 N300 Firmware | - |
| Chiyu-Tech | Semac D2 N300 | - |
| Chiyu-Tech | Semac S1 Osdp Firmware | - |
| Chiyu-Tech | Semac S1 Osdp | - |
| Chiyu-Tech | Bf-631 Firmware | - |
| Chiyu-Tech | Bf-631 | - |
| Chiyu-Tech | Bf-630 Firmware | - |
| Chiyu-Tech | Bf-630 | - |
| Chiyu-Tech | Webpass Firmware | - |
| Chiyu-Tech | Webpass | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162934/CHIYU-IoT-Denial-Of-Service.htmlExploitThird Party AdvisoryVDB Entry
- https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devicesExploitThird Party Advisory
- https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-ExploitThird Party Advisory
- https://www.chiyu-tech.com/msg/message-Firmware-update-87.htmlVendor Advisory
- http://packetstormsecurity.com/files/162934/CHIYU-IoT-Denial-Of-Service.htmlExploitThird Party AdvisoryVDB Entry
- https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devicesExploitThird Party Advisory
- https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-ExploitThird Party Advisory
- https://www.chiyu-tech.com/msg/message-Firmware-update-87.htmlVendor Advisory
FAQ
What is CVE-2021-31642?
CVE-2021-31642 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explor...
How severe is CVE-2021-31642?
CVE-2021-31642 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31642?
Check the references section above for vendor advisories and patch information. Affected products include: Chiyu-Tech Semac S2 Firmware, Chiyu-Tech Semac S2, Chiyu-Tech Semac D1 Firmware, Chiyu-Tech Semac D1, Chiyu-Tech Semac D2 Firmware.