« Volver al listado

CVE-2021-45918

Estado: ModificadaAlta (7.5)—

NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-45918",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "NHI",
          "product": "health insurance web service component",
          "versions": [
            {
              "status": "affected",
              "version": "515BE7DE5BCE446177FEE8A6E0665093"
            }
          ],
          "platforms": [
            "Windows"
          ]
        },
        {
          "vendor": "NHI",
          "product": "health insurance web service component",
          "versions": [
            {
              "status": "affected",
              "version": "42fcc36541e716e23de77d5f325b186a"
            }
          ],
          "platforms": [
            "Mac"
          ]
        },
        {
          "vendor": "NHI",
          "product": "health insurance web service component",
          "versions": [
            {
              "status": "affected",
              "version": "52EACB7CA2B4D0A5A869DF01079BF4D6"
            }
          ],
          "platforms": [
            "Linux(Ubuntu)"
          ]
        },
        {
          "vendor": "NHI",
          "product": "health insurance web service component",
          "versions": [
            {
              "status": "affected",
              "version": "52EACB7CA2B4D0A5A869DF01079BF4D6"
            }
          ],
          "platforms": [
            "Linux(Fedora)"
          ]
        }
      ]
    }
  ],
  "published": "2022-06-20T06:15:08.503",
  "references": [
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6227-eaf49-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6227-eaf49-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service."
    },
    {
      "lang": "es",
      "value": "El componente del servicio web del seguro de salud de NHI no comprueba suficientemente la longitud de las cadenas de entrada, lo que puede resultar en un ataque de desbordamiento del búfer en la región heap de la memoria. Un atacante remoto puede explotar esta vulnerabilidad para inundar el espacio de memoria reservado para el programa, con el fin de interrumpir el servicio sin autenticación, lo que requiere un reinicio del sistema para recuperar el servicio"
    }
  ],
  "lastModified": "2026-06-17T04:14:15.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nhi:health_insurance_web_service_component:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0379276F-4782-4249-82EF-A26C6EE14E8B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}