Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.
References
Link | Resource |
---|---|
https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY | Vendor Advisory |
https://www.motorolasolutions.com/en_us/about/trust-center/security.html | Vendor Advisory |
https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY | Vendor Advisory |
https://www.motorolasolutions.com/en_us/about/trust-center/security.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
21 Nov 2024, 06:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY - Vendor Advisory | |
References | () https://www.motorolasolutions.com/en_us/about/trust-center/security.html - Vendor Advisory |
22 Dec 2021, 19:20
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:motorola:t201_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:motorola:t205_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:motorola:t200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:motorola:t290_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:motorola:t204:-:*:*:*:*:*:*:* cpe:2.3:h:motorola:t101:-:*:*:*:*:*:*:* cpe:2.3:h:motorola:t100:-:*:*:*:*:*:*:* cpe:2.3:o:motorola:t103_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:motorola:t290:-:*:*:*:*:*:*:* cpe:2.3:o:motorola:t102_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:motorola:t100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:motorola:t204_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:motorola:t200:-:*:*:*:*:*:*:* cpe:2.3:o:motorola:t101_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:motorola:t201:-:*:*:*:*:*:*:* cpe:2.3:h:motorola:t205:-:*:*:*:*:*:*:* cpe:2.3:h:motorola:t102:-:*:*:*:*:*:*:* cpe:2.3:h:motorola:t008:-:*:*:*:*:*:*:* cpe:2.3:o:motorola:t008_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:motorola:t103:-:*:*:*:*:*:*:* |
|
CWE | CWE-79 | |
References | (MISC) https://www.motorolasolutions.com/en_us/about/trust-center/security.html - Vendor Advisory | |
References | (CONFIRM) https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 4.8 |
15 Dec 2021, 08:00
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-12-15 07:15
Updated : 2024-11-21 06:17
NVD link : CVE-2021-38701
Mitre link : CVE-2021-38701
CVE.ORG link : CVE-2021-38701
JSON object : View
Products Affected
motorola
- t201
- t103
- t205_firmware
- t102
- t100_firmware
- t200_firmware
- t008_firmware
- t290_firmware
- t204_firmware
- t204
- t100
- t201_firmware
- t102_firmware
- t290
- t103_firmware
- t101_firmware
- t200
- t008
- t101
- t205
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')