Vulnerability Details CVE-2021-20120
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2021-20120
-
cpe:2.3:h:commscope:arris_surfboard_sb8200:-
-
cpe:2.3:o:commscope:arris_surfboard_sb8200_firmware:ab01.02.053.01_112320_193.0a.nsh