8.8
CVE-2018-21170
- EPSS 0.1%
- Veröffentlicht 27.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:04
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ R7800 Firmware Version < 1.0.2.40
Netgear ≫ Ex2700 Firmware Version < 1.0.1.28
Netgear ≫ Wn2000rpt Firmware Version < 1.0.1.20
Netgear ≫ Wn3000rp Firmware Version < 1.0.2.50
Netgear ≫ Wn3100rp Firmware Version < 1.0.0.56
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.272 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
| cve@mitre.org | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.