Lucene search

K
cveTenableCVE-2021-20137
HistoryDec 09, 2021 - 4:15 p.m.

CVE-2021-20137

2021-12-0916:15:07
CWE-79
tenable
web.nvd.nist.gov
39
cve-2021-20137
reflected cross-site scripting
gryphon tower router
nvd
security vulnerability
web interface
javascript execution

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.236

Percentile

96.7%

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router’s web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim’s browser.

Affected configurations

Nvd
Node
gryphonconnectgryphon_towerMatch-
AND
gryphonconnectgryphon_tower_firmwareRange04.0004.12
VendorProductVersionCPE
gryphonconnectgryphon_tower-cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*
gryphonconnectgryphon_tower_firmware*cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Gryphon Tower router",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "<= 04.0004.12 (Current)"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.236

Percentile

96.7%

Related for CVE-2021-20137