Vulnerabilities > Sealevel > Seaconnect 370W Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2021-21959 Improper Certificate Validation vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc.
network
high complexity
sealevel CWE-295
8.1
2022-02-04 CVE-2021-21962 Out-of-bounds Write vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc.
network
high complexity
sealevel CWE-787
8.1
2022-02-04 CVE-2021-21964 Missing Authentication for Critical Function vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc.
network
low complexity
sealevel CWE-306
7.4
2022-02-04 CVE-2021-21968 Unspecified vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc.
network
high complexity
sealevel
8.3
2022-02-04 CVE-2021-21969 Out-of-bounds Write vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc.
network
high complexity
sealevel CWE-787
8.1
2022-02-04 CVE-2021-21970 Out-of-bounds Write vulnerability in Sealevel Seaconnect 370W Firmware 1.3.34
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc.
network
high complexity
sealevel CWE-787
8.1