Lucene search

K
nvd[email protected]NVD:CVE-2021-39243
HistoryAug 23, 2021 - 5:15 a.m.

CVE-2021-39243

2021-08-2305:15:08
CWE-352
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

35.3%

Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

Affected configurations

NVD
Node
altusnexto_nx3003Match-
AND
altusnexto_nx3003_firmwareMatch1.8.11.0
Node
altusnexto_nx3004Match-
AND
altusnexto_nx3004_firmwareMatch1.8.11.0
Node
altusnexto_nx3005Match-
AND
altusnexto_nx3005_firmwareMatch1.8.11.0
Node
altusnexto_nx3010Match-
AND
altusnexto_nx3010_firmwareMatch1.8.3.0
Node
altusnexto_nx3020Match-
AND
altusnexto_nx3020_firmwareMatch1.8.3.0
Node
altusnexto_nx3030Match-
AND
altusnexto_nx3030_firmwareMatch1.8.3.0
Node
altusnexto_nx5100Match-
AND
altusnexto_nx5100_firmwareMatch1.8.11.0
Node
altusnexto_nx5101Match-
AND
altusnexto_nx5101_firmwareMatch1.8.11.0
Node
altusnexto_nx5110_firmwareMatch1.1.2.8
AND
altusnexto_nx5110Match-
Node
altusnexto_nx5210_firmwareMatch1.1.2.8
AND
altusnexto_nx5210Match-
Node
altusnexto_xpress_xp300_firmwareMatch1.8.11.0
AND
altusnexto_xpress_xp300Match-
Node
altusnexto_xpress_xp315_firmwareMatch1.8.11.0
AND
altusnexto_xpress_xp315Match-
Node
altusnexto_xpress_xp325_firmwareMatch1.8.11.0
AND
altusnexto_xpress_xp325Match-
Node
altusnexto_xpress_xp340_firmwareMatch1.8.11.0
AND
altusnexto_xpress_xp340Match-
Node
altushadron_xtorm_hx3040_firmwareMatch1.7.58.0
AND
altushadron_xtorm_hx3040Match-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

35.3%

Related for NVD:CVE-2021-39243