CVE-2021-38701

Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:t008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t008:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:motorola:t100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:motorola:t101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t101:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:motorola:t102_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t102:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:motorola:t103_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t103:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:motorola:t200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t200:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:motorola:t201_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t201:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:motorola:t204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t204:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:motorola:t205_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t205:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:motorola:t290_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:t290:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:17

Type Values Removed Values Added
References () https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY - Vendor Advisory () https://support.avigilon.com/s/feed/0D54y00006l9eCMCAY - Vendor Advisory
References () https://www.motorolasolutions.com/en_us/about/trust-center/security.html - Vendor Advisory () https://www.motorolasolutions.com/en_us/about/trust-center/security.html - Vendor Advisory

Information

Published : 2021-12-15 07:15

Updated : 2024-11-21 06:17


NVD link : CVE-2021-38701

Mitre link : CVE-2021-38701

CVE.ORG link : CVE-2021-38701


JSON object : View

Products Affected

motorola

  • t204_firmware
  • t204
  • t101_firmware
  • t102_firmware
  • t103_firmware
  • t290
  • t201
  • t205
  • t101
  • t205_firmware
  • t290_firmware
  • t200
  • t103
  • t008_firmware
  • t008
  • t100
  • t100_firmware
  • t201_firmware
  • t200_firmware
  • t102
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')