5.4
CVE-2021-20843
- EPSS 0.28%
- Veröffentlicht 24.11.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:15
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yamaha ≫ Rtx830 Firmware Version <= 15.02.17
Yamaha ≫ Nvr510 Firmware Version <= 15.01.18
Yamaha ≫ Nvr700w Firmware Version <= 15.00.19
Yamaha ≫ Rtx1210 Firmware Version <= 14.01.38
Ntt-west ≫ Biz Box Rtx830 Firmware Version <= 15.02.17
Ntt-west ≫ Biz Box Nvr510 Firmware Version < 15.01.18
Ntt-west ≫ Biz Box Nvr700w Firmware Version <= 15.00.19
Ntt-west ≫ Biz Box Rtx1210 Firmware Version <= 14.01.38
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.514 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.