CVE-2021-45918
Published: Jun 20, 2022
Modified: Sep 17, 2024
CVSS v3.1
7.5
Description
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service.
| Vendor | Product | Versions |
|---|---|---|
NHI | health insurance web service component | affected 515BE7DE5BCE446177FEE8A6E0665093 |
NHI | health insurance web service component | affected 42fcc36541e716e23de77d5f325b186a |
NHI | health insurance web service component | affected 52EACB7CA2B4D0A5A869DF01079BF4D6 |
NHI | health insurance web service component | affected 52EACB7CA2B4D0A5A869DF01079BF4D6 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now