Skip to content
COOEY

EXPOSURES › CVE-2021-27132

CVE-2021-27132

CRITICAL
DETAIL
SourceNVD · cve Published2021-02-27 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27132 ↗
SHAME 35/100

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CISA and security press condemn SerComm's CRLF injection vulnerability as critical and widely exploited, with no evidence of praise or mitigation in provided sources.
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosed
"SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header."
CISA ↗ severe-fallout -0.80
CISA ICS Advisory issued
"ICS Advisories | CISA"
www.cvefind.com ↗ severe-fallout -0.50
Vulnerability listed in CISA KEV
"CISA - Exploited vuln."
www.databreachtoday.com ↗ severe-fallout +0.00
Irrelevant content
www.iheart.com ↗ severe-fallout +0.00
Irrelevant content
classactionu.org ↗ severe-fallout +0.00
Irrelevant content
www.security.org ↗ severe-fallout +0.00
Irrelevant content
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.