7.7
CVE-2017-18860
- EPSS 0.07%
- Published 29.04.2020 14:15:14
- Last modified 21.11.2024 03:21:06
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.
Data is provided by the National Vulnerability Database (NVD)
Netgear ≫ Fs752tp Firmware Version <= 5.4.2.19
Netgear ≫ Gs108t Firmware Version <= 5.4.2.29
Netgear ≫ Gs110tp Firmware Version <= 5.4.2.29
Netgear ≫ Gs418tpp Firmware Version <= 6.6.2.6
Netgear ≫ Gs510tlp Firmware Version <= 6.6.2.6
Netgear ≫ Gs510tp Firmware Version <= 5.04.2.27
Netgear ≫ Gs510tpp Firmware Version <= 6.6.2.6
Netgear ≫ Gs716t Firmware Version <= 5.4.2.27
Netgear ≫ Gs716t Firmware Version <= 6.3.1.16
Netgear ≫ Gs724t Firmware Version <= 5.4.2.27
Netgear ≫ Gs724t Firmware Version <= 6.3.1.16
Netgear ≫ Gs728tpsb Firmware Version <= 5.3.0.29
Netgear ≫ Gs728tsb Firmware Version <= 5.3.0.29
Netgear ≫ Gs728txs Firmware Version <= 6.1.0.35
Netgear ≫ Gs748t Firmware Version <= 5.4.2.27
Netgear ≫ Gs748t Firmware Version <= 6.3.1.16
Netgear ≫ Gs752tpsb Firmware Version <= 5.3.0.29
Netgear ≫ Gs752tsb Firmware Version <= 5.3.0.29
Netgear ≫ Gs752txs Firmware Version <= 6.1.0.35
Netgear ≫ M4200 Firmware Version <= 12.0.2.10
Netgear ≫ M4300 Firmware Version <= 12.0.2.10
Netgear ≫ M5300 Firmware Version <= 11.0.0.28
Netgear ≫ M6100 Firmware Version <= 11.0.0.28
Netgear ≫ M7100 Firmware Version <= 11.0.0.28
Netgear ≫ S3300 Firmware Version <= 6.6.1.4
Netgear ≫ Xs708t Firmware Version <= 6.6.0.11
Netgear ≫ Xs712t Firmware Version <= 6.1.0.34
Netgear ≫ Xs716t Firmware Version <= 6.6.0.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.226 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.7 | 2.5 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:P
|
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.