An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.armis.com/PwnedPiper - Third Party Advisory | |
References | () https://www.swisslog-healthcare.com - Product | |
References | () https://www.swisslog-healthcare.com/-/media/swisslog-healthcare/documents/customer-service/armis-documents/cve-2021-37163-bulletin---default-credentials-for-the-telnet-server.pdf?rev=da64c389a475494985b9fd2c2c508542&hash=466A7109AF08EBFF3756B2C25968ED5E - Vendor Advisory | |
References | () https://www.swisslog-healthcare.com/en-us/customer-care/security-information/cve-disclosures#:~:text=CVE%20Disclosures%20%20%20%20Vulnerability%20Name%20%2C%20%20CVE-2021-37164%20%204%20more%20rows%20 - |
10 Aug 2021, 18:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:swisslog-healthcare:hmi-3_control_panel:-:*:*:*:*:*:*:* cpe:2.3:o:swisslog-healthcare:hmi-3_control_panel_firmware:*:*:*:*:*:*:*:* |
|
CWE | CWE-798 | |
References | (MISC) https://www.swisslog-healthcare.com/en-us/customer-care/security-information/cve-disclosures#:~:text=CVE%20Disclosures%20%20%20%20Vulnerability%20Name%20,%20%20CVE-2021-37164%20%204%20more%20rows%20 - Vendor Advisory | |
References | (MISC) https://www.swisslog-healthcare.com/-/media/swisslog-healthcare/documents/customer-service/armis-documents/cve-2021-37163-bulletin---default-credentials-for-the-telnet-server.pdf?rev=da64c389a475494985b9fd2c2c508542&hash=466A7109AF08EBFF3756B2C25968ED5E - Vendor Advisory | |
References | (MISC) https://www.swisslog-healthcare.com - Product | |
References | (MISC) https://www.armis.com/PwnedPiper - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
02 Aug 2021, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-02 13:15
Updated : 2024-11-21 06:14
NVD link : CVE-2021-37163
Mitre link : CVE-2021-37163
CVE.ORG link : CVE-2021-37163
JSON object : View
Products Affected
swisslog-healthcare
- hmi-3_control_panel
- hmi-3_control_panel_firmware
CWE
CWE-798
Use of Hard-coded Credentials