CVE-2021-37167

CRITICAL

HMI3 Control Panel Firmware < 7.2.5.7 - Privilege Escalation via Default Credentials

Title source: llm
STIX 2.1

Description

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.

Scores

CVSS v3 9.8
EPSS 0.0174
EPSS Percentile 74.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
swisslog-healthcare/hmi-3_control_panel_firmware < 7.2.5.7
Published Aug 02, 2021
Tracked Since Feb 18, 2026