5.9

CVE-2020-13245

Exploit

Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

Data is provided by the National Vulnerability Database (NVD)
NetgearR6120 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6120 Version-
NetgearR6220 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6220 Version-
NetgearR6350 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6350 Version-
NetgearR6400 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6400 Version-
NetgearR6400 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6400 Versionv2
NetgearR6800 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6800 Version-
NetgearR6850 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR6850 Version-
NetgearR7000p Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR7000p Version-
NetgearR7800 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR7800 Version-
NetgearR8000 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR8000 Version-
NetgearR9000 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearR9000 Version-
NetgearRax120 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearRax120 Version-
NetgearRbr20 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearRbr20 Version-
NetgearXr300 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearXr300 Version-
NetgearXr500 Firmware Version >= v1.0.9.6_1.2.19 <= v1.0.11.100_10.2.100
   NetgearXr500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.261
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.