5.4

CVE-2021-20843

Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.

Data is provided by the National Vulnerability Database (NVD)
YamahaRtx830 Firmware Version <= 15.02.17
   YamahaRtx830 Version-
YamahaNvr510 Firmware Version <= 15.01.18
   YamahaNvr510 Version-
YamahaNvr700w Firmware Version <= 15.00.19
   YamahaNvr700w Version-
YamahaRtx1210 Firmware Version <= 14.01.38
   YamahaRtx1210 Version-
Ntt-westBiz Box Rtx830 Firmware Version <= 15.02.17
   Ntt-westBiz Box Rtx830 Version-
Ntt-westBiz Box Nvr510 Firmware Version < 15.01.18
   Ntt-westBiz Box Nvr510 Version-
Ntt-westBiz Box Nvr700w Firmware Version <= 15.00.19
   Ntt-westBiz Box Nvr700w Version-
Ntt-westBiz Box Rtx1210 Firmware Version <= 14.01.38
   Ntt-westBiz Box Rtx1210 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.487
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.