Cross-Site Script Inclusion Vulnerability in Yamaha Networking Products
CVE-2021-20843

5.4MEDIUM

Key Information:

Vendor
CVE Published:
24 November 2021

What is CVE-2021-20843?

A cross-site script inclusion vulnerability exists in the web GUI of several Yamaha networking devices, allowing remote authenticated attackers to manipulate device settings through specially crafted web pages. This flaw affects multiple models, including RTX830, NVR510, NVR700W, and RTX1210, running specific firmware versions earlier than noted releases. Organizations using these devices should implement necessary patches and security measures to mitigate risks associated with unauthorized configuration changes.

Affected Version(s)

RTX830, NVR510, NVR700W, RTX1210 RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, RTX1210 Rev.14.01.38 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.