Vulnerability Name:
CCN-230047
Published:
2022-06-29
Updated:
2022-06-29
Summary:
An unspecified error in NETGEAR devices could allow a remote authenticated attacker to execute commands on the system.
CVSS v3 Severity:
8.4 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
)
7.3 High
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Adjacent
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
7.7 High
(CCN CVSS v2 Vector:
AV:A/AC:L/Au:S/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Adjacent_Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Consequences:
Gain Access
References:
Source: XF
Type: UNKNOWN
netgear-psv20200219-cmd-exec(230047)
Source: CCN
Type: NETGEAR Security Advisory: PSV-2020-0219
Security Advisory for Post-Authentication Command Injection on Some Routers and WiFi Systems
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/h:netgear:r7000p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk752:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk852:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mk62:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ms60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7900:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7960p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax200:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax45:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax50:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax75:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mr60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7900p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax15:-:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
netgear
r7000p -
netgear
r8000 -
netgear
rbk752 -
netgear
rbr750 -
netgear
rbs750 -
netgear
rbk852 -
netgear
rbr850 -
netgear
rbs850 -
netgear
mk62 -
netgear
ms60 -
netgear
r7000 -
netgear
r7900 -
netgear
r7960p -
netgear
rax20 -
netgear
rax200 -
netgear
rax45 -
netgear
rax50 -
netgear
rax75 -
netgear
rax80 -
netgear
mr60 -
netgear
r7900p -
netgear
rax15 -