CVE-2021-20119: High severity commscope arris surfboard sb8200 vulnerability
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20119?
CVE-2021-20119 is a vulnerability that allows any logged-in user to change the administrator password of the Arris SurfBoard SB8200.
What is the severity of CVE-2021-20119?
The severity of CVE-2021-20119 is high with a CVSS score of 7.1.
How can the safety measures bypass be exploited in CVE-2021-20119?
The vulnerability in CVE-2021-20119 allows any logged-in user to bypass the safety measures implemented in the password change utility of the Arris SurfBoard SB8200.
Is the Commscope Arris Surfboard Sb8200 firmware version ab01.02.053.01_112320_193.0a.nsh affected by CVE-2021-20119?
Yes, the Commscope Arris Surfboard Sb8200 firmware version ab01.02.053.01_112320_193.0a.nsh is affected by CVE-2021-20119.
How can I mitigate the vulnerability in CVE-2021-20119?
To mitigate CVE-2021-20119, it is recommended to update the firmware of the Arris SurfBoard SB8200 to a non-vulnerable version and restrict access to the password change utility.