CVE Database
/

CVE-2021-45918

Back to search

CVE-2021-45918

Published: Jun 20, 2022

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service.

VendorProductVersions

NHI

health insurance web service component

affected
515BE7DE5BCE446177FEE8A6E0665093

NHI

health insurance web service component

affected
42fcc36541e716e23de77d5f325b186a

NHI

health insurance web service component

affected
52EACB7CA2B4D0A5A869DF01079BF4D6

NHI

health insurance web service component

affected
52EACB7CA2B4D0A5A869DF01079BF4D6

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now