VulnerabilityModified
CVE-2021-20712
Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall…
MEDIUM 5.3EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall function.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- nec/aterm wg2600hs firmware · nec/aterm wx3000hp firmware
- Source
- vultures@jpcert.or.jp
References
- https://jpn.nec.com/security-info/secinfo/nv21-010.htmlMitigation, Vendor Advisory
- https://jvn.jp/en/jp/JVN29739718/index.htmlThird Party Advisory
- https://jpn.nec.com/security-info/secinfo/nv21-010.htmlMitigation, Vendor Advisory
- https://jvn.jp/en/jp/JVN29739718/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.