// For flags

CVE-2021-31642

CHIYU IoT Devices - Denial of Service (DoS)

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

5
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.

Se presenta una condición de denegación de servicio tras un desbordamiento de enteros en varios dispositivos IoT de CHIYU Technology, incluyendo BIOSENSE, Webpass, y BF-630, BF-631, y SEMAC. La vulnerabilidad puede ser explorada mediante el envío de un entero inesperado (superiores a 32 bits) en el parámetro page que bloqueará el portal web y hará que no esté disponible hasta un reinicio del dispositivo

CHIYU IoT devices suffer from an integer overflow denial of service vulnerability. Affected devices include BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC with firmware versions prior to June 2021.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-23 CVE Reserved
  • 2021-06-01 CVE Published
  • 2021-06-03 First Exploit
  • 2024-08-03 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2 Firmware
Search vendor "Chiyu-tech" for product "Semac S2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2
Search vendor "Chiyu-tech" for product "Semac S2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1 Firmware
Search vendor "Chiyu-tech" for product "Semac D1 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1
Search vendor "Chiyu-tech" for product "Semac D1"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2
Search vendor "Chiyu-tech" for product "Semac D2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4 Firmware
Search vendor "Chiyu-tech" for product "Semac D4 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4
Search vendor "Chiyu-tech" for product "Semac D4"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3 Firmware
Search vendor "Chiyu-tech" for product "Semac S3v3 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3
Search vendor "Chiyu-tech" for product "Semac S3v3"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 N300 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300
Search vendor "Chiyu-tech" for product "Semac D2 N300"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp Firmware
Search vendor "Chiyu-tech" for product "Semac S1 Osdp Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp
Search vendor "Chiyu-tech" for product "Semac S1 Osdp"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631 Firmware
Search vendor "Chiyu-tech" for product "Bf-631 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631
Search vendor "Chiyu-tech" for product "Bf-631"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630 Firmware
Search vendor "Chiyu-tech" for product "Bf-630 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630
Search vendor "Chiyu-tech" for product "Bf-630"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Webpass Firmware
Search vendor "Chiyu-tech" for product "Webpass Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Webpass
Search vendor "Chiyu-tech" for product "Webpass"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Biosense Firmware
Search vendor "Chiyu-tech" for product "Biosense Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Biosense
Search vendor "Chiyu-tech" for product "Biosense"
--
Safe