Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-36799. PoCs published by robertguetzkow.
AI-analyzed exploit summary This repository contains a functional password recovery tool for ETS5 (KNX ETS5) projects, exploiting a vulnerability (CVE-2021-36799) to extract obfuscated passwords from configuration files. The tool parses XML-based project files and deobfuscates stored credentials.
Description
KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Exploits (1)
This repository contains a functional password recovery tool for ETS5 (KNX ETS5) projects, exploiting a vulnerability (CVE-2021-36799) to extract obfuscated passwords from configuration files. The tool parses XML-based project files and deobfuscates stored credentials.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H