CVE-2021-20844 Vulnerability Details

  /     /     /  

CVE-2021-20844 Metadata Quick Info

CVE Published: 24/11/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: jpcert | Vendor: Yamaha Corporation | Product: RTX830, NVR510, NVR700W, RTX1210
Status : PUBLISHED

CVE-2021-20844 Description

Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Neutralization of HTTP Headers for Scripting Syntax
Source: Yamaha Corporation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).