CVE-2021-44564: High severity kalkitech sync241-m1 vulnerability

Published Jan 6, 2022
·
Updated

A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. The attack exploits the unsecured communication channel used between the administration tool Easyconnect and the SYNC device (in the affected family of SYNC products).

Affected Software

80 affected components
Kalkitech Sync241-m1 Firmware<=4.15.3
Kalkitech Sync241-m1
Kalkitech Sync241-m2 Firmware<=4.15.3
Kalkitech Sync241-m2
Kalkitech Sync241-m4 Firmware<=4.15.3
Kalkitech Sync241-m4
Kalkitech Sync261-m1 Firmware<=4.15.3
Kalkitech Sync261-m1
Kalkitech Sync2000-m1 Firmware<=4.15.3
Kalkitech Sync2000-m1
Kalkitech Sync2000-m2 Firmware<=4.15.3
Kalkitech Sync2000-m2
Kalkitech Sync2000-m4 Firmware<=4.15.3
Kalkitech Sync2000-m4
Kalkitech Sync2101-m1 Firmware<=4.15.3
Kalkitech Sync2101-m1
Kalkitech Sync2101-m2 Firmware<=4.15.3
Kalkitech Sync2101-m2
Kalkitech Sync2101-m6 Firmware<=4.15.3
Kalkitech Sync2101-m6
Kalkitech Sync2101-m7 Firmware<=4.15.3
Kalkitech Sync2101-m7
Kalkitech Sync2101-m8 Firmware<=4.15.3
Kalkitech Sync2101-m8
Kalkitech Sync2111-m2 Firmware<=4.15.3
Kalkitech Sync2111-m2
Kalkitech Sync2111-m3 Firmware<=4.15.3
Kalkitech Sync2111-m3
Kalkitech Sync3000-m1 Firmware<=4.15.3
Kalkitech Sync3000-m1
Kalkitech Sync3000-m2 Firmware<=4.15.3
Kalkitech Sync3000-m2
Kalkitech Sync3000-m3 Firmware<=4.15.3
Kalkitech Sync3000-m3
Kalkitech Sync3000-m4 Firmware<=4.15.3
Kalkitech Sync3000-m4
Kalkitech Sync3000-m12 Firmware<=4.15.3
Kalkitech Sync3000-m12
Kalkitech Sync221-m1 Firmware<=4.15.3
Kalkitech Sync221-m1
All of the following
Kalkitech Sync241-m1 Firmware<=4.15.3
Kalkitech Sync241-m1
All of the following
Kalkitech Sync241-m2 Firmware<=4.15.3
Kalkitech Sync241-m2
All of the following
Kalkitech Sync241-m4 Firmware<=4.15.3
Kalkitech Sync241-m4
All of the following
Kalkitech Sync261-m1 Firmware<=4.15.3
Kalkitech Sync261-m1
All of the following
Kalkitech Sync2000-m1 Firmware<=4.15.3
Kalkitech Sync2000-m1
All of the following
Kalkitech Sync2000-m2 Firmware<=4.15.3
Kalkitech Sync2000-m2
All of the following
Kalkitech Sync2000-m4 Firmware<=4.15.3
Kalkitech Sync2000-m4
All of the following
Kalkitech Sync2101-m1 Firmware<=4.15.3
Kalkitech Sync2101-m1
All of the following
Kalkitech Sync2101-m2 Firmware<=4.15.3
Kalkitech Sync2101-m2
All of the following
Kalkitech Sync2101-m6 Firmware<=4.15.3
Kalkitech Sync2101-m6
All of the following
Kalkitech Sync2101-m7 Firmware<=4.15.3
Kalkitech Sync2101-m7
All of the following
Kalkitech Sync2101-m8 Firmware<=4.15.3
Kalkitech Sync2101-m8
All of the following
Kalkitech Sync2111-m2 Firmware<=4.15.3
Kalkitech Sync2111-m2
All of the following
Kalkitech Sync2111-m3 Firmware<=4.15.3
Kalkitech Sync2111-m3
All of the following
Kalkitech Sync3000-m1 Firmware<=4.15.3
Kalkitech Sync3000-m1
All of the following
Kalkitech Sync3000-m2 Firmware<=4.15.3
Kalkitech Sync3000-m2
All of the following
Kalkitech Sync3000-m3 Firmware<=4.15.3
Kalkitech Sync3000-m3
All of the following
Kalkitech Sync3000-m4 Firmware<=4.15.3
Kalkitech Sync3000-m4
All of the following
Kalkitech Sync3000-m12 Firmware<=4.15.3
Kalkitech Sync3000-m12
All of the following
Kalkitech Sync221-m1 Firmware<=4.15.3
Kalkitech Sync221-m1

Event History

Jan 6, 2022
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-44564?

CVE-2021-44564 has a moderate severity level due to the potential for unauthorized access to device configurations.

2

How do I fix CVE-2021-44564?

To fix CVE-2021-44564, update affected SYNC firmware to version 4.15.4 or later.

3

What types of devices are affected by CVE-2021-44564?

CVE-2021-44564 affects specific SYNC devices including the Sync241, Sync261, Sync2000, Sync2101, Sync2111, and Sync3000 models.

4

How does the CVE-2021-44564 vulnerability work?

CVE-2021-44564 allows attackers with network access to download and modify device configuration files.

5

What are the risks associated with CVE-2021-44564?

The risks of CVE-2021-44564 include unauthorized changes to device settings, leading to potential operational disruptions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203