CVE-2021-38701
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/12/2021
Last modified:
22/12/2021
Description
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:motorola:t008_firmware:*:*:*:*:*:*:*:* | 2.2.0.86 (excluding) | |
| cpe:2.3:h:motorola:t008:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t100_firmware:*:*:*:*:*:*:*:* | 2.6.0.180 (excluding) | |
| cpe:2.3:h:motorola:t100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t101_firmware:*:*:*:*:*:*:*:* | 2.6.0.180 (excluding) | |
| cpe:2.3:h:motorola:t101:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t102_firmware:*:*:*:*:*:*:*:* | 2.6.0.180 (excluding) | |
| cpe:2.3:h:motorola:t102:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t103_firmware:*:*:*:*:*:*:*:* | 2.6.0.180 (excluding) | |
| cpe:2.3:h:motorola:t103:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t200_firmware:*:*:*:*:*:*:*:* | 4.10.0.68 (excluding) | |
| cpe:2.3:h:motorola:t200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t201_firmware:*:*:*:*:*:*:*:* | 4.10.0.68 (excluding) | |
| cpe:2.3:h:motorola:t201:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:t204_firmware:*:*:*:*:*:*:*:* | 3.28.0.166 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



