The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-7577 The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-03T17:30:07.478Z

Reserved: 2020-12-17T00:00:00

Link: CVE-2021-20120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-21T17:15:07.690

Modified: 2024-11-21T05:45:57.663

Link: CVE-2021-20120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.