← Back to CVEs
CVE-2021-37160
CRITICAL9.8
Description
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published8/2/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
swisslog-healthcare:hmi-3_control_panelswisslog-healthcare:hmi-3_control_panel_firmware
Weaknesses (CWE)
CWE-347
References
https://www.armis.com/PwnedPiper(cve@mitre.org)
https://www.swisslog-healthcare.com(cve@mitre.org)
https://www.armis.com/PwnedPiper(af854a3a-2127-422b-91ae-364da2661108)
https://www.swisslog-healthcare.com(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.