CVE-2021-20677
Estado: ModificadaBaja (3.1)—
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 3.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.92%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-20677",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "NEC Platforms, Ltd.",
"product": "UNIVERGE Aspire series PBX",
"versions": [
{
"status": "affected",
"version": "UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00"
}
]
}
]
}
],
"published": "2021-03-26T09:15:11.950",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN12737530/index.html",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.necplatforms.co.jp/en/press/security_adv.html",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN12737530/index.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.necplatforms.co.jp/en/press/security_adv.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command."
},
{
"lang": "es",
"value": "UNIVERGE Aspire series PBX (UNIVERGE Aspire WX desde versiones 1.00 hasta 3.51, UNIVERGE Aspire UX desde versiones 1.00 hasta 9.70, UNIVERGE SV9100 desde versiones 1.00 hasta 10.70 y SL2100 desde versiones 1.00 hasta 3.00) permite a un atacante autenticado remoto causar la caída del sistema y una denegación de servicio ( DoS) mediante el envío de un comando especialmente diseñado."
}
],
"lastModified": "2026-06-17T03:34:13.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:necplatforms:univerge_aspire_wx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C1A17B4-9A99-4772-BEE5-D69D6B4B4BEE",
"versionEndIncluding": "3.51",
"versionStartIncluding": "1.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:necplatforms:univerge_aspire_wx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E57AF072-9F43-4F37-891B-1B68BA1D9C91"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:necplatforms:univerge_aspire_ux_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE390008-23F2-44BD-863C-C574DD7A97E0",
"versionEndIncluding": "9.70",
"versionStartIncluding": "1.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:necplatforms:univerge_aspire_ux:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A68A0CB3-7B3C-431D-A339-4CF1C5EBC0C6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:necplatforms:univerge_sv9100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D611FCE0-8B1B-43C3-BBE9-E7FA6801F947",
"versionEndIncluding": "10.70",
"versionStartIncluding": "1.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:necplatforms:univerge_sv9100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "38FE4F0F-5112-4214-A8E0-A4858F368C69"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:necplatforms:sl2100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36778BAB-500F-444F-93F4-FBBE28ECDB40",
"versionEndIncluding": "3.00",
"versionStartIncluding": "1.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:necplatforms:sl2100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "129B972F-8F69-48B8-B2A2-E3AD109EF05F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}