vendor:
BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC
by:
sirpedrotavares
6.5
CVSS
MEDIUM
Denial of Service (DoS)
190
CWE
Product Name: BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC
Affected Version From: all firmware versions < June 2021
Affected Version To: June 2021
Patch Exists: YES
Related CWE: CVE-2021-31642
CPE: h:chiyu_technology:biosense
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=146102, https://www.infosecmatter.com/nessus-plugin-library/?id=31949, https://www.infosecmatter.com/nessus-plugin-library/?id=31439, https://www.infosecmatter.com/nessus-plugin-library/?id=137753, https://www.infosecmatter.com/nessus-plugin-library/?id=22213, https://www.infosecmatter.com/nessus-plugin-library/?id=57739, https://www.infosecmatter.com/nessus-plugin-library/?id=21504, https://www.infosecmatter.com/nessus-plugin-library/?id=16064, https://www.infosecmatter.com/nessus-plugin-library/?id=18530, https://www.infosecmatter.com/nessus-plugin-library/?id=20281
Platforms Tested: BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC
2021
CHIYU IoT Devices – Denial of Service (DoS)
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
Mitigation:
The laters firmware versions released by CHIYU Technology should be installed in order to mitigate this vulnerability.