CVE-2021-20844
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD
Description
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.02.17 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx830 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.01.18 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Nvr510 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.00.19 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Nvr700w | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.01.38 |
| Running on/with | Platform Versions |
|---|---|
Yamaha Rtx1210 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.02.17 |
| Running on/with | Platform Versions |
|---|---|
Ntt West Biz Box Rtx830 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 15.01.18 |
| Running on/with | Platform Versions |
|---|---|
Ntt West Biz Box Nvr510 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 15.00.19 |
| Running on/with | Platform Versions |
|---|---|
Ntt West Biz Box Nvr700w | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.01.38 |
| Running on/with | Platform Versions |
|---|---|
Ntt West Biz Box Rtx1210 | All versions |
References (8)
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: vultures@jpcert.or.jp
MitigationThird Party Advisory
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.