CVE-2021-45917

HIGH

Shockwall System - Authenticated LAN Server-Side Request Forgery

Title source: manual
STIX 2.1

Description

The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-side request forgery (SSRF) attack on another agent computer, resulting in arbitrary code execution for controlling the system or disrupting service.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5433-77f6f-1.html

Scores

CVSS v3 8.0
EPSS 0.0045
EPSS Percentile 35.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
sun_moon_jingyao/network_computer_terminal_protection_system_firmware < 7.20.0401
Published Jan 03, 2022
Tracked Since Feb 18, 2026