CVE-2021-20676 describes an access restriction bypass vulnerability affecting M-System DL8 series devices (types A, B, C, D, and E) running firmware versions prior to 3.0. This flaw allows remote authenticated attackers to perform unauthorized operations through unspecified vectors. The vulnerability has a CVSSv3.1 score of 4.3 (Medium), indicating a low-complexity attack that can be executed remotely by an authenticated user, potentially leading to a loss of integrity. While the EPSS score is low, suggesting a low probability of exploitation, the FAUCET Risk Score is 9/100. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are also minimal, aligning with the typical low attention for many vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.81CPE matchmatch criteria | cpe:2.3:o:m-system:dl8-a_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.77CPE matchmatch criteria | cpe:2.3:o:m-system:dl8-b_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.99CPE matchmatch criteria | cpe:2.3:o:m-system:dl8-c_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.91CPE matchmatch criteria | cpe:2.3:o:m-system:dl8-d_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.12CPE matchmatch criteria | cpe:2.3:o:m-system:dl8-e_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.