CVE-2021-37165

CRITICAL

Swisslog-healthcare Hmi-3 Control Panel Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

Scores

CVSS v3 9.8
EPSS 0.0500
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (1)
swisslog-healthcare/hmi-3_control_panel_firmware < 7.2.5.7
Published Aug 02, 2021
Tracked Since Feb 18, 2026