8.8
CVE-2018-21170
- EPSS 0.1%
- Veröffentlicht 27.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:04
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ R7800 Firmware Version < 1.0.2.40
Netgear ≫ Ex2700 Firmware Version < 1.0.1.28
Netgear ≫ Wn2000rpt Firmware Version < 1.0.1.20
Netgear ≫ Wn3000rp Firmware Version < 1.0.2.50
Netgear ≫ Wn3100rp Firmware Version < 1.0.0.56
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.275 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
cve@mitre.org | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.