peter bassill · operator
$ cve CVE-2021-37164 JSON

CVE-2021-37164

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.4% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2021-08-02
Last modified2026-06-17

Affected (2)

VendorProduct
swisslog-healthcarehmi-3 control panel
swisslog-healthcarehmi-3 control panel firmware

References

→ the Explorer  ·  watch your stack  ·  NVD