Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33017


The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.


Published

2021-12-27T19:15:08.230

Last Modified

2024-11-21T06:08:08.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-288

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System philips intellibridge_ec40_firmware ≤ c.00.04 Yes
Hardware philips intellibridge_ec40 - No
Operating System philips intellibridge_ec80_firmware ≤ c.00.04 Yes
Hardware philips intellibridge_ec80 - No

References