CVE-2021-20677
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service…
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.
- CVSS 3.1
- 3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- necplatforms/univerge aspire wx firmware · necplatforms/univerge aspire ux firmware · necplatforms/univerge sv9100 firmware · necplatforms/sl2100 firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN12737530/index.htmlThird Party Advisory
- https://www.necplatforms.co.jp/en/press/security_adv.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN12737530/index.htmlThird Party Advisory
- https://www.necplatforms.co.jp/en/press/security_adv.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.