CVE-2021-27132
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
27/02/2021
Last modified:
05/03/2021
Description
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:sercomm:agcombo_vd625_firmware:agsot_2.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:h:sercomm:agcombo_vd625:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page