CVE-2021-37373
Summary
| CVE | CVE-2021-37373 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-03 18:15:00 UTC |
| Updated | 2023-11-07 03:36:00 UTC |
| Description | ** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Teradek | Slice | - | All | All | All |
| Operating System | Teradek | Slice Firmware | All | All | All | All |
| Operating System | Teradek | Slice Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Tyler Butler | Teradek Cross-Site Scripting Vulnerability Advisory | MISC | tbutler.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.