Vulnerability Details CVE-2021-31642
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.302
EPSS Ranking 96.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.8
Products affected by CVE-2021-31642
-
cpe:2.3:h:chiyu-tech:bf-630:-
-
cpe:2.3:h:chiyu-tech:bf-631:-
-
cpe:2.3:h:chiyu-tech:biosense:-
-
cpe:2.3:h:chiyu-tech:semac_d1:-
-
cpe:2.3:h:chiyu-tech:semac_d2:-
-
cpe:2.3:h:chiyu-tech:semac_d2_n300:-
-
cpe:2.3:h:chiyu-tech:semac_d4:-
-
cpe:2.3:h:chiyu-tech:semac_s1_osdp:-
-
cpe:2.3:h:chiyu-tech:semac_s2:-
-
cpe:2.3:h:chiyu-tech:semac_s3v3:-
-
cpe:2.3:h:chiyu-tech:webpass:-
-
cpe:2.3:o:chiyu-tech:bf-630_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-631_firmware:-
-
cpe:2.3:o:chiyu-tech:biosense_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d1_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d2_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d2_n300_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d4_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s1_osdp_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s2_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s3v3_firmware:-
-
cpe:2.3:o:chiyu-tech:webpass_firmware:-