CVE-2021-20120

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/10/2021
Last modified:
27/10/2021

Description

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:commscope:arris_surfboard_sb8200_firmware:ab01.02.053.01_112320_193.0a.nsh:*:*:*:*:*:*:*
cpe:2.3:h:commscope:arris_surfboard_sb8200:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools