Vulnerability Description
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Auerswald | Compact 5500R Ip Firmware | <= 8.0b |
| Auerswald | Compact 5500R Ip | - |
| Auerswald | Compact 5200R Ip Firmware | <= 8.0b |
| Auerswald | Compact 5200R Ip | - |
| Auerswald | Compact 5000R Ip Firmware | <= 8.0b |
| Auerswald | Compact 5000R Ip | - |
| Auerswald | Compact 4000 Ip Firmware | <= 8.0b |
| Auerswald | Compact 4000R Ip | - |
| Auerswald | Commander 6000R Ip Firmware | <= 8.0b |
| Auerswald | Commander 6000R Ip | - |
| Auerswald | Commander 6000Rx Ip Firmware | <= 8.0b |
| Auerswald | Commander 6000Rx Ip | - |
| Auerswald | Commander Business\(19\"\) Ip Firmware | <= 8.0b |
| Auerswald | Commander Business\(19\"\) Ip | - |
| Auerswald | Commander Basic.2\(19\"\) Ip Firmware | <= 8.0b |
| Auerswald | Commander Basic.2\(19\"\) Ip | - |
| Auerswald | Compact 5010 Voip Ip Firmware | <= 8.0b |
| Auerswald | Compact 5010 Voip Ip | - |
| Auerswald | Compact 5020 Voip Ip Firmware | <= 8.0b |
| Auerswald | Compact 5020 Voip Ip | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/165163/Auerswald-COMpact-8.0B-Privilege-EscExploitThird Party AdvisoryVDB Entry
- https://www.redteam-pentesting.de/advisories/rt-sa-2021-005ExploitThird Party Advisory
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerabiExploitThird Party Advisory
- http://packetstormsecurity.com/files/165163/Auerswald-COMpact-8.0B-Privilege-EscExploitThird Party AdvisoryVDB Entry
- https://www.redteam-pentesting.de/advisories/rt-sa-2021-005ExploitThird Party Advisory
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerabiExploitThird Party Advisory
FAQ
What is CVE-2021-40857?
CVE-2021-40857 is a vulnerability with a CVSS score of 8.8 (HIGH). Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
How severe is CVE-2021-40857?
CVE-2021-40857 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40857?
Check the references section above for vendor advisories and patch information. Affected products include: Auerswald Compact 5500R Ip Firmware, Auerswald Compact 5500R Ip, Auerswald Compact 5200R Ip Firmware, Auerswald Compact 5200R Ip, Auerswald Compact 5000R Ip Firmware.