// For flags

CVE-2021-37471

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH command-line.

Los dispositivos Cradlepoint IBR900-600 que ejecutan versiones anteriores a la versión 7.21.10 son vulnerables a una secuencia de escape de shell restringida que proporciona a un atacante la capacidad de denegar simultáneamente la disponibilidad de la consola de NetCloud Manager del dispositivo, la consola local y la línea de comandos SSH

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-25 CVE Reserved
  • 2021-11-07 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cradlepoint
Search vendor "Cradlepoint"
Ibr600c Firmware
Search vendor "Cradlepoint" for product "Ibr600c Firmware"
< 7.21.0
Search vendor "Cradlepoint" for product "Ibr600c Firmware" and version " < 7.21.0"
-
Affected
in Cradlepoint
Search vendor "Cradlepoint"
Ibr600c
Search vendor "Cradlepoint" for product "Ibr600c"
--
Safe
Cradlepoint
Search vendor "Cradlepoint"
Ibr600 Firmware
Search vendor "Cradlepoint" for product "Ibr600 Firmware"
< 7.21.0
Search vendor "Cradlepoint" for product "Ibr600 Firmware" and version " < 7.21.0"
-
Affected
in Cradlepoint
Search vendor "Cradlepoint"
Ibr600
Search vendor "Cradlepoint" for product "Ibr600"
--
Safe
Cradlepoint
Search vendor "Cradlepoint"
Ibr900 Firmware
Search vendor "Cradlepoint" for product "Ibr900 Firmware"
< 7.21.0
Search vendor "Cradlepoint" for product "Ibr900 Firmware" and version " < 7.21.0"
-
Affected
in Cradlepoint
Search vendor "Cradlepoint"
Ibr900
Search vendor "Cradlepoint" for product "Ibr900"
--
Safe