Vulnerability Description
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vitec | Exterity Avediaserver | <= 2021-04-30 |
| Vitec | Exterity Avediastream Encoders Firmware | <= 2021-04-30 |
| Vitec | Exterity Avediastream Encoders | - |
| Vitec | Avediastream M9605 Firmware | <= 2021-04-30 |
| Vitec | Avediastream M9605 | - |
| Vitec | Avediastream M9400 Firmware | <= 2021-04-30 |
| Vitec | Avediastream M9400 | - |
| Vitec | Avediastream M9405 Firmware | <= 2021-04-30 |
| Vitec | Avediastream M9405 | - |
| Vitec | Avediastream M9305 Firmware | <= 2021-04-30 |
| Vitec | Avediastream M9305 | - |
| Vitec | Avediastream R9300 Firmware | <= 2021-04-30 |
| Vitec | Avediastream R9300 | - |
| Vitec | Avediastream R9310 Firmware | <= 2021-04-30 |
| Vitec | Avediastream R9310 | - |
| Vitec | Avediastream M9325 Firmware | <= 2021-04-30 |
| Vitec | Avediastream M9325 | - |
| Vitec | Avediastream R9350 Firmware | <= 2021-04-30 |
| Vitec | Avediastream R9350 | - |
Related Weaknesses (CWE)
References
- https://whitehoodhacker.net/posts/2021-10-04-the-big-rickExploitThird Party Advisory
- https://www.exterity.comVendor Advisory
- https://whitehoodhacker.net/posts/2021-10-04-the-big-rickExploitThird Party Advisory
- https://www.exterity.comVendor Advisory
FAQ
What is CVE-2021-42109?
CVE-2021-42109 is a vulnerability with a CVSS score of 9.8 (CRITICAL). VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
How severe is CVE-2021-42109?
CVE-2021-42109 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-42109?
Check the references section above for vendor advisories and patch information. Affected products include: Vitec Exterity Avediaserver, Vitec Exterity Avediastream Encoders Firmware, Vitec Exterity Avediastream Encoders, Vitec Avediastream M9605 Firmware, Vitec Avediastream M9605.