5.4
CVE-2021-20843
- EPSS 0.28%
- Published 24.11.2021 16:15:13
- Last modified 21.11.2024 05:47:15
- Source vultures@jpcert.or.jp
- Teams watchlist Login
- Open Login
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
Data is provided by the National Vulnerability Database (NVD)
Yamaha ≫ Rtx830 Firmware Version <= 15.02.17
Yamaha ≫ Nvr510 Firmware Version <= 15.01.18
Yamaha ≫ Nvr700w Firmware Version <= 15.00.19
Yamaha ≫ Rtx1210 Firmware Version <= 14.01.38
Ntt-west ≫ Biz Box Rtx830 Firmware Version <= 15.02.17
Ntt-west ≫ Biz Box Nvr510 Firmware Version < 15.01.18
Ntt-west ≫ Biz Box Nvr700w Firmware Version <= 15.00.19
Ntt-west ≫ Biz Box Rtx1210 Firmware Version <= 14.01.38
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.487 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.