First published: Thu Oct 21 2021(Updated: )
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Commscope Arris Surfboard Sb8200 Firmware | =ab01.02.053.01_112320_193.0a.nsh | |
Commscope Arris Surfboard Sb8200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20120 is a vulnerability in the administration web interface of the Arris Surfboard SB8200 that allows for cross-site request forgery attacks.
CVE-2021-20120 allows attackers to make configuration changes on the Arris Surfboard SB8200 without user consent, such as changing the administrative password.
The severity of CVE-2021-20120 is rated as high with a CVSS score of 8.8.
Yes, the Arris Surfboard SB8200 with firmware version ab01.02.053.01_112320_193.0a.nsh is vulnerable to CVE-2021-20120.
To fix CVE-2021-20120, it is recommended to update the firmware of the Arris Surfboard SB8200 to a version that includes the necessary protections against cross-site request forgery attacks.