Vulnerability Name:
CCN-230037
Published:
2022-06-29
Updated:
2022-06-29
Summary:
An unspecified error in NETGEAR devices could allow a remote attacker to read arbitrary files on the system.
CVSS v3 Severity:
6.5 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
)
5.7 Medium
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Adjacent
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
6.1 Medium
(CCN CVSS v2 Vector:
AV:A/AC:L/Au:N/C:C/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Adjacent_Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
None
Availibility (A):
None
Vulnerability Consequences:
Obtain Information
References:
Source: XF
Type: UNKNOWN
netgear-psv20210006-file-read(230037)
Source: CCN
Type: NETGEAR Security Advisory: PSV-2021-0006
Security Advisory for Arbitrary File Read on Some Routers and WiFi system
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/h:netgear:rbr50:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs50:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk50:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r9000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7800:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax120:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:xr500:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk40:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr40:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs40:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:xr450:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:d7800:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:xr700:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk22:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk12:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr10:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs10:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8900:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax10:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax120v2:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax70:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:lbr1020:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:lbr20:-:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
netgear
rbr50 -
netgear
rbs50 -
netgear
rbk50 -
netgear
r9000 -
netgear
r7800 -
netgear
rax120 -
netgear
rbr20 -
netgear
xr500 -
netgear
rbs20 -
netgear
rbk40 -
netgear
rbr40 -
netgear
rbs40 -
netgear
xr450 -
netgear
d7800 -
netgear
xr700 -
netgear
rbk22 -
netgear
rbk12 -
netgear
rbr10 -
netgear
rbs10 -
netgear
r8900 -
netgear
rax10 -
netgear
rax120v2 -
netgear
rax70 -
netgear
lbr1020 -
netgear
lbr20 -