Vulnerabilities > CVE-2021-20119 - Incorrect Authorization vulnerability in Commscope Arris Surfboard Sb8200 Firmware Ab01.02.053.01112320193.0A.Nsh

047910
CVSS 7.1 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
high complexity
commscope
CWE-863

Summary

The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.

Common Weakness Enumeration (CWE)