A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HSealevel Seaconnect 370w
HWSealevelall versionsSealevel Seaconnect 370w Firmware
OSSealevel1.3.34
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-21965CRITICAL9.3PL ✓same product
DoS w funkcji zdalnej konfiguracji SeaMax urządzenia SeaConnect 370W
CVE-2021-21960CRITICAL10.0PL ✓same product
Stack-based buffer overflow w LLMNR w Sealevel SeaConnect 370W — RCE
CVE-2021-21961CRITICAL10.0PL ✓same product
Stack-based buffer overflow w NBNS na Sealevel SeaConnect 370W — RCE
CVE-2021-21964HIGH7.4same product
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. S...
CVE-2021-21962HIGH8.1same product
A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Syste...