Vulnerability Name:
CCN-230123
Published:
2022-06-29
Updated:
2022-06-29
Summary:
An unspecified error in NETGEAR devices could allow a remote authenticated attacker to execute commands on the system.
CVSS v3 Severity:
8.4 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
)
7.3 High
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Adjacent
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
7.7 High
(CCN CVSS v2 Vector:
AV:A/AC:L/Au:S/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Adjacent_Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Consequences:
Gain Access
References:
Source: XF
Type: UNKNOWN
netgear-psv20200494-cmd-exec(230123)
Source: CCN
Type: NETGEAR Security Advisory: PSV-2020-0494
Security Advisory for Post-Authentication Command Injection on Some Routers and WiFi Systems
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/h:netgear:r7000p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r6400:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r6400:v2:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk752:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk852:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mk62:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7900:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7960p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax200:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax45:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax50:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax75:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mr60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8000p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ms60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:xr1000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:cbr750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:lax20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax43:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax40:v2:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax35:v2:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mr80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ms80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax15:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mk83:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r6300:v2:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
netgear
r7000p -
netgear
r8000 -
netgear
r6400 -
netgear
r6400 v2
netgear
rbk752 -
netgear
rbr750 -
netgear
rbs750 -
netgear
rbk852 -
netgear
rbr850 -
netgear
rbs850 -
netgear
mk62 -
netgear
r7000 -
netgear
r7850 -
netgear
r7900 -
netgear
r7960p -
netgear
rax20 -
netgear
rax200 -
netgear
rax45 -
netgear
rax50 -
netgear
rax75 -
netgear
rax80 -
netgear
mr60 -
netgear
r8000p -
netgear
ms60 -
netgear
xr1000 -
netgear
cbr750 -
netgear
lax20 -
netgear
rax43 -
netgear
rax40 v2
netgear
rax35 v2
netgear
mr80 -
netgear
ms80 -
netgear
rax15 -
netgear
mk83 -
netgear
r6300 v2