7.2

CVE-2018-21163

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200Bv4 before 1.0.0.102, DGN2200v4 before 1.0.0.102, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.22, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150 before 1.0.0.38, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6300v2 before 1.0.4.22, R6900P before 1.3.0.18, R7000P before 1.3.0.18, R7300DST before 1.0.0.62, R7900P before 1.3.0.10, R8000 before 1.0.4.12, R8000P before 1.3.0.10, WN2500RPv2 before 1.0.1.52, and WNDR3400v3 before 1.0.1.18.

Data is provided by the National Vulnerability Database (NVD)
NetgearDgn2200b Firmware Version < 1.0.0.102
   NetgearDgn2200b Versionv4
NetgearDgn2200 Firmware Version < 1.0.0.102
   NetgearDgn2200 Versionv4
NetgearEx3700 Firmware Version < 1.0.0.70
   NetgearEx3700 Version-
NetgearEx3800 Firmware Version < 1.0.0.70
   NetgearEx3800 Version-
NetgearEx6000 Firmware Version < 1.0.0.30
   NetgearEx6000 Version-
NetgearEx6100 Firmware Version < 1.0.2.22
   NetgearEx6100 Version-
NetgearEx6120 Firmware Version < 1.0.0.40
   NetgearEx6120 Version-
NetgearEx6130 Firmware Version < 1.0.0.22
   NetgearEx6130 Version-
NetgearEx6150 Firmware Version < 1.0.0.38
   NetgearEx6150 Version-
NetgearEx6200 Firmware Version < 1.0.3.86
   NetgearEx6200 Version-
NetgearEx7000 Firmware Version < 1.0.0.64
   NetgearEx7000 Version-
NetgearR6300 Firmware Version < 1.0.4.22
   NetgearR6300 Versionv2
NetgearR6900p Firmware Version < 1.3.0.18
   NetgearR6900p Version-
NetgearR7000p Firmware Version < 1.3.0.18
   NetgearR7000p Version-
NetgearR7300dst Firmware Version < 1.0.0.62
   NetgearR7300dst Version-
NetgearR7900p Firmware Version < 1.3.0.10
   NetgearR7900p Version-
NetgearR8000 Firmware Version < 1.0.4.12
   NetgearR8000 Version-
NetgearR8000p Firmware Version < 1.3.0.10
   NetgearR8000p Version-
NetgearWn2500rp Firmware Version < 1.0.1.52
   NetgearWn2500rp Versionv2
NetgearWndr3400 Firmware Version < 1.0.1.18
   NetgearWndr3400 Versionv3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.33% 0.532
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
cve@mitre.org 6.8 0.9 5.9
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.