peter bassill · operator
$ cve CVE-2021-37160 JSON

CVE-2021-37160

9.8
CRITICAL · CVSS 3.1 · EPSS 8.2% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.23% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-347
On CISA KEVno
Public exploitnone known
Published2021-08-02
Last modified2026-06-17

Affected (2)

VendorProduct
swisslog-healthcarehmi-3 control panel
swisslog-healthcarehmi-3 control panel firmware

References

→ the Explorer  ·  watch your stack  ·  NVD