CVE-2021-20843

Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:yamaha:rtx830_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:rtx830:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:yamaha:nvr510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:nvr510:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:yamaha:nvr700w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:nvr700w:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:yamaha:rtx1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:rtx1210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ntt-west:biz_box_rtx830_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_rtx830:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ntt-west:biz_box_nvr510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_nvr510:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ntt-west:biz_box_nvr700w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_nvr700w:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ntt-west:biz_box_rtx1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_rtx1210:-:*:*:*:*:*:*:*

History

30 Nov 2021, 07:11

Type Values Removed Values Added
CWE CWE-829
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 5.4
References (MISC) https://jvn.jp/en/vu/JVNVU91161784/index.html - (MISC) https://jvn.jp/en/vu/JVNVU91161784/index.html - Mitigation, Third Party Advisory
References (MISC) https://business.ntt-east.co.jp/topics/2021/11_09.html - (MISC) https://business.ntt-east.co.jp/topics/2021/11_09.html - Mitigation, Vendor Advisory
References (MISC) https://www.ntt-west.co.jp/smb/kiki_info/info/211109.html - (MISC) https://www.ntt-west.co.jp/smb/kiki_info/info/211109.html - Mitigation, Vendor Advisory
References (MISC) http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU91161784.html - (MISC) http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU91161784.html - Mitigation, Vendor Advisory
CPE cpe:2.3:h:ntt-west:biz_box_nvr700w:-:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:nvr510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:nvr700w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:biz_box_rtx1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:rtx830:-:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_rtx830:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:biz_box_nvr510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_rtx1210:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:biz_box_rtx830_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ntt-west:biz_box_nvr510:-:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:nvr510:-:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:rtx1210:-:*:*:*:*:*:*:*
cpe:2.3:h:yamaha:nvr700w:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:biz_box_nvr700w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rtx1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rtx830_firmware:*:*:*:*:*:*:*:*

24 Nov 2021, 16:18

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-24 16:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-20843

Mitre link : CVE-2021-20843

CVE.ORG link : CVE-2021-20843


JSON object : View

Products Affected

yamaha

  • nvr700w_firmware
  • rtx1210
  • rtx830_firmware
  • nvr510_firmware
  • nvr700w
  • rtx830
  • rtx1210_firmware
  • nvr510

ntt-west

  • biz_box_nvr510
  • biz_box_rtx830_firmware
  • biz_box_nvr510_firmware
  • biz_box_rtx1210
  • biz_box_nvr700w
  • biz_box_rtx1210_firmware
  • biz_box_rtx830
  • biz_box_nvr700w_firmware
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere