5.7

CVE-2021-20844

Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yamaha ≫ Rtx830 Firmware Version <= 15.02.17
   Yamaha ≫ Rtx830 Version -
Yamaha ≫ Nvr510 Firmware Version <= 15.01.18
   Yamaha ≫ Nvr510 Version -
Yamaha ≫ Nvr700w Firmware Version <= 15.00.19
   Yamaha ≫ Nvr700w Version -
Yamaha ≫ Rtx1210 Firmware Version <= 14.01.38
   Yamaha ≫ Rtx1210 Version -
Ntt-west ≫ Biz Box Rtx830 Firmware Version <= 15.02.17
   Ntt-west ≫ Biz Box Rtx830 Version -
Ntt-west ≫ Biz Box Nvr510 Firmware Version < 15.01.18
   Ntt-west ≫ Biz Box Nvr510 Version -
Ntt-west ≫ Biz Box Nvr700w Firmware Version <= 15.00.19
   Ntt-west ≫ Biz Box Nvr700w Version -
Ntt-west ≫ Biz Box Rtx1210 Firmware Version <= 14.01.38
   Ntt-west ≫ Biz Box Rtx1210 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU91161784.html
Vendor Advisory
Mitigation
https://business.ntt-east.co.jp/topics/2021/11_09.html
Vendor Advisory
Mitigation
https://jvn.jp/en/vu/JVNVU91161784/index.html
Third Party Advisory
Mitigation
https://www.ntt-west.co.jp/smb/kiki_info/info/211109.html
Vendor Advisory
Mitigation