Vulnerability Details CVE-2021-20843
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-20843
-
cpe:2.3:h:ntt-west:biz_box_nvr510:-
-
cpe:2.3:h:ntt-west:biz_box_nvr700w:-
-
cpe:2.3:h:ntt-west:biz_box_rtx1210:-
-
cpe:2.3:h:ntt-west:biz_box_rtx830:-
-
cpe:2.3:h:yamaha:nvr510:-
-
cpe:2.3:h:yamaha:nvr700w:-
-
cpe:2.3:h:yamaha:rtx1210:-
-
cpe:2.3:h:yamaha:rtx830:-
-
cpe:2.3:o:ntt-west:biz_box_nvr510_firmware:-
-
cpe:2.3:o:ntt-west:biz_box_nvr700w_firmware:-
-
cpe:2.3:o:ntt-west:biz_box_nvr700w_firmware:15.00.19
-
cpe:2.3:o:ntt-west:biz_box_rtx1210_firmware:-
-
cpe:2.3:o:ntt-west:biz_box_rtx1210_firmware:14.01.38
-
cpe:2.3:o:ntt-west:biz_box_rtx830_firmware:-
-
cpe:2.3:o:ntt-west:biz_box_rtx830_firmware:15.02.17
-
cpe:2.3:o:yamaha:nvr510_firmware:15.01.14
-
cpe:2.3:o:yamaha:nvr510_firmware:15.01.18
-
cpe:2.3:o:yamaha:nvr700w_firmware:15.00.15
-
cpe:2.3:o:yamaha:nvr700w_firmware:15.00.19
-
cpe:2.3:o:yamaha:rtx1210_firmware:14.01.33
-
cpe:2.3:o:yamaha:rtx1210_firmware:14.01.38
-
cpe:2.3:o:yamaha:rtx830_firmware:15.02.09
-
cpe:2.3:o:yamaha:rtx830_firmware:15.02.17