8.8
CVE-2017-18775
- EPSS 0.2%
- Veröffentlicht 22.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 03:20:53
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ R6100 Firmware Version < 1.0.1.12
Netgear ≫ R7500 Firmware Version < 1.0.0.108
Netgear ≫ Wndr3700 Firmware Version < 1.0.2.86
Netgear ≫ Wndr4300 Firmware Version < 1.0.2.88
Netgear ≫ Wndr4300 Firmware Version < 1.0.0.48
Netgear ≫ Wndr4500 Firmware Version < 1.0.0.48
Netgear ≫ Wnr2000 Firmware Version < 1.0.0.42
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.424 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
cve@mitre.org | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.