« Volver al listado

CVE-2021-32458

Estado: ModificadaAlta (7.8)—

Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-32458",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Trend Micro",
          "product": "Trend Micro Home Network Security",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.604 and below"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-27T11:15:07.313",
  "references": [
    {
      "url": "https://helpcenter.trendmicro.com/en-us/article/TMKA-10337",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1231",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://helpcenter.trendmicro.com/en-us/article/TMKA-10337",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1231",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability."
    },
    {
      "lang": "es",
      "value": "La versión 6.6.604 y anteriores de Trend Micro Home Network Security son vulnerables a una vulnerabilidad de desbordamiento del búfer basada en la pila de iotcl que podría permitir a un atacante emitir un iotcl especialmente diseñado que podría conducir a la ejecución de código en los dispositivos afectados. Un atacante debe obtener primero la capacidad de ejecutar código con pocos privilegios en el dispositivo de destino para poder explotar esta vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T03:52:58.903",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trendmicro:home_network_security:*:*:*:en:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CA71C14-AE1C-44AF-8CFF-8461DBA0CA78",
              "versionEndIncluding": "6.6.604"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:home_network_security:*:*:*:ja:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EE779A2-BE6E-4EF1-B22E-D2ED7CA3C74D",
              "versionEndIncluding": "6.6.604"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:home_network_security:*:*:*:zh:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5C7D541-00E5-4BF7-8191-9BA2BB5CD931",
              "versionEndIncluding": "6.6.604"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@trendmicro.com"
}