CVE-2021-20699
Last modified
CVE-2021-20699 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker a buffer overflow and to execute remote code by sending long parameters that contains specific characters in http request.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker a buffer overflow and to execute remote code by sending long parameters that contains specific characters in http request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sharp-Nec-Displays | Un462a Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un462va Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un492s Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un492vs Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un552a Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un552s Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un552vs Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un552 Firmware | <= r1.300 |
| Sharp-Nec-Displays | Un552v Firmware | <= r1.300 |
| Sharp-Nec-Displays | Ux552s Firmware | <= r1.300 |
| Sharp-Nec-Displays | Ux552 Firmware | <= r1.300 |
| Sharp-Nec-Displays | V864q Firmware | <= r2.000 |
| Sharp-Nec-Displays | C861q Firmware | <= r2.000 |
| Sharp-Nec-Displays | P754q Firmware | <= r2.000 |
| Sharp-Nec-Displays | V754q Firmware | <= r2.000 |
| Sharp-Nec-Displays | C751q Firmware | <= r2.000 |
| Sharp-Nec-Displays | V984q Firmware | <= r2.000 |
| Sharp-Nec-Displays | C981q Firmware | <= r2.000 |
| Sharp-Nec-Displays | P654q Firmware | <= r2.000 |
| Sharp-Nec-Displays | V654q Firmware | <= r2.000 |
| Sharp-Nec-Displays | C651q Firmware | <= r2.000 |
| Sharp-Nec-Displays | V554q Firmware | <= r2.000 |
| Sharp-Nec-Displays | P404 Firmware | <= r3.201 |
| Sharp-Nec-Displays | P484 Firmware | <= r3.201 |
| Sharp-Nec-Displays | P554 Firmware | <= r3.201 |
| Sharp-Nec-Displays | V404 Firmware | <= r3.201 |
| Sharp-Nec-Displays | V484 Firmware | <= r3.201 |
| Sharp-Nec-Displays | V554 Firmware | <= r3.201 |
| Sharp-Nec-Displays | V404-T Firmware | <= r3.201 |
| Sharp-Nec-Displays | V484-T Firmware | <= r3.201 |
| Sharp-Nec-Displays | V554-T Firmware | <= r3.201 |
| Sharp-Nec-Displays | C501 Firmware | <= r2.000 |
| Sharp-Nec-Displays | C551 Firmware | <= r2.000 |
| Sharp-Nec-Displays | C431 Firmware | <= r2.000 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20699?
How severe is CVE-2021-20699?
How do I fix CVE-2021-20699?
Are you affected by CVE-2021-20699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
