ZeroHour

CVE-2021-37160

CVSS 3.1
9.8 critical
EPSS
8%p95
Published
()
Modified
Description

A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.

Vendors
swisslog-healthcare
Products
hmi-3 control panel firmware
Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news