CVE-2021-20119 is a high-severity vulnerability affecting the Arris SurfBoard SB8200 modem, allowing any logged-in user to bypass security measures and change the administrator password. With a CVSS score of 7.1, this vulnerability has an adjacent attack vector and high impact on confidentiality, integrity, and availability, despite high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ab01.02.053.01_112320_193.0a.nshCPE matchmatch criteria | cpe:2.3:o:commscope:arris_surfboard_sb8200_firmware:ab01.02.053.01_112320_193.0a.nsh:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Arris SurfBoard SB8200 Insecure Password Change Utility
Nov 8, 2021Arris SurfBoard SB8200 Insecure Password Change Utility
Nov 8, 2021Arris SurfBoard SB8200 Insecure Password Change Utility
Nov 8, 2021