Lucene search

K

Arris Surfboard Sb8200 Firmware Security Vulnerabilities

cve
cve

CVE-2021-20119

The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.

7.1CVSS

7.1AI Score

0.0005EPSS

2021-11-09 07:15 PM
18
cve
cve

CVE-2021-20120

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

8.8CVSS

8.6AI Score

0.001EPSS

2021-10-21 05:15 PM
23