MEDIUM · 4.8

CVE-2021-38701

Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3...

Vulnerability Description

Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MotorolaT008 Firmware< 2.2.0.86
MotorolaT008-
MotorolaT100 Firmware< 2.6.0.180
MotorolaT100-
MotorolaT101 Firmware< 2.6.0.180
MotorolaT101-
MotorolaT102 Firmware< 2.6.0.180
MotorolaT102-
MotorolaT103 Firmware< 2.6.0.180
MotorolaT103-
MotorolaT200 Firmware< 4.10.0.68
MotorolaT200-
MotorolaT201 Firmware< 4.10.0.68
MotorolaT201-
MotorolaT204 Firmware< 3.28.0.166
MotorolaT204-
MotorolaT205 Firmware< 4.12.0.62
MotorolaT205-
MotorolaT290 Firmware< 4.4.0.80
MotorolaT290-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-38701?

CVE-2021-38701 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3...

How severe is CVE-2021-38701?

CVE-2021-38701 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-38701?

Check the references section above for vendor advisories and patch information. Affected products include: Motorola T008 Firmware, Motorola T008, Motorola T100 Firmware, Motorola T100, Motorola T101 Firmware.