Security Vulnerability in SYNC Devices by Kalkitech
CVE-2021-44564

8.1HIGH

Key Information:

Vendor

Kalkitech

Vendor
CVE Published:
6 January 2022

What is CVE-2021-44564?

A significant security flaw affects certain SYNC devices, enabling an attacker with network access and knowledge of the device's IP address to download and potentially modify the configuration file. This vulnerability exploits an unsecured communication channel between the administration tool, Easyconnect, and the affected SYNC products. It underscores the critical need for enhancing communication security and access controls within networked devices to prevent unauthorized configuration changes.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.