peter bassill · operator
$ cve CVE-2021-40422 JSON

CVE-2021-40422

10.0
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS6.2% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2022-04-14
Last modified2026-06-17

Affected (2)

VendorProduct
swiftsensorssg3-1010
swiftsensorssg3-1010 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD