MEDIUM · 5.3

CVE-2021-20712

Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed fro...

Vulnerability Description

Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall function.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NecAterm Wg2600Hs Firmware<= 1.5.1
NecAterm Wg2600Hs-
NecAterm Wx3000Hp Firmware<= 1.1.2
NecAterm Wx3000Hp-

References

FAQ

What is CVE-2021-20712?

CVE-2021-20712 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed fro...

How severe is CVE-2021-20712?

CVE-2021-20712 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20712?

Check the references section above for vendor advisories and patch information. Affected products include: Nec Aterm Wg2600Hs Firmware, Nec Aterm Wg2600Hs, Nec Aterm Wx3000Hp Firmware, Nec Aterm Wx3000Hp.