A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.armis.com/PwnedPiper - Broken Link | |
References | () https://www.swisslog-healthcare.com - Product | |
References | () https://www.swisslog-healthcare.com/-/media/swisslog-healthcare/documents/customer-service/armis-documents/cve-2021-37164-bulletin---off-by-three-stack-overflow-in-tcptxthread.pdf?rev=daf615075c71484c8059c906872a51e6&hash=1FCC1A5D921E231D71E6B95A9AA8B741 - Vendor Advisory | |
References | () https://www.swisslog-healthcare.com/en-us/customer-care/security-information/cve-disclosures#:~:text=CVE%20Disclosures%20%20%20%20Vulnerability%20Name%20%2C%20%20CVE-2021-37164%20%204%20more%20rows%20 - |
07 Nov 2023, 03:36
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-08-02 13:15
Updated : 2024-11-21 06:14
NVD link : CVE-2021-37164
Mitre link : CVE-2021-37164
CVE.ORG link : CVE-2021-37164
JSON object : View
Products Affected
swisslog-healthcare
- hmi-3_control_panel_firmware
- hmi-3_control_panel
CWE
CWE-787
Out-of-bounds Write