6.5

CVE-2017-18862

Certain NETGEAR devices are affected by authentication bypass. This affects JGS516PE before 2017-05-11, JGS524Ev2 before 2017-05-11, JGS524PE before 2017-05-11, GS105Ev2 before 2017-05-11, GS105PE before 2017-05-11, GS108Ev3 before 2017-05-11, GS108PEv3 before 2017-05-11, GS116Ev2 before 2017-05-11, GSS108E before 2017-05-11, GSS116E before 2017-05-11, XS708Ev2 before 2017-05-11, and XS716E before 2017-05-11.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetgearJgs516pe Firmware Version < 2017-05-11
   NetgearJgs516pe Version-
NetgearJgs524e Firmware Version < 2017-05-11
   NetgearJgs524e Versionv2
NetgearJgs524pe Firmware Version < 2017-05-11
   NetgearJgs524pe Version-
NetgearGs105e Firmware Version < 2017-05-11
   NetgearGs105e Versionv2
NetgearGs105pe Firmware Version < 2017-05-11
   NetgearGs105pe Version-
NetgearGs108e Firmware Version < 2017-05-11
   NetgearGs108e Versionv3
NetgearGs108pe Firmware Version < 2017-05-11
   NetgearGs108pe Versionv3
NetgearGs116e Firmware Version < 2017-05-11
   NetgearGs116e Versionv2
NetgearGss108e Firmware Version < 2017-05-11
   NetgearGss108e Version-
NetgearGss116e Firmware Version < 2017-05-11
   NetgearGss116e Version-
NetgearXs708e Firmware Version < 2017-05-11
   NetgearXs708e Versionv2
NetgearXs716e Firmware Version < 2017-05-11
   NetgearXs716e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.252
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.