EXPOSURES › CVE-2021-27132
CVE-2021-27132
CRITICAL
DETAIL
SourceNVD · cve
Published2021-02-27
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27132 ↗
SHAME 35/100
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CISA and security press condemn SerComm's CRLF injection vulnerability as critical and widely exploited, with no evidence of praise or mitigation in provided sources.
Critical vulnerability disclosed
"SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header."
Irrelevant content
Irrelevant content
Irrelevant content
Irrelevant content
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.