8.4
CVE-2021-29073
- EPSS 0.1%
- Published 23.03.2021 07:15:13
- Last modified 21.11.2024 06:00:39
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.66, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, R7960P before 1.4.1.66, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, and RAX200 before 1.0.3.106.
Data is provided by the National Vulnerability Database (NVD)
Netgear ≫ R8000p Firmware Version < 1.4.1.66
Netgear ≫ Mk62 Firmware Version < 1.0.6.110
Netgear ≫ Mr60 Firmware Version < 1.0.6.110
Netgear ≫ Ms60 Firmware Version < 1.0.6.110
Netgear ≫ R7960p Firmware Version < 1.4.1.66
Netgear ≫ R7900p Firmware Version < 1.4.1.66
Netgear ≫ Rax15 Firmware Version < 1.0.2.82
Netgear ≫ Rax20 Firmware Version < 1.0.2.82
Netgear ≫ Rax45 Firmware Version < 1.0.2.72
Netgear ≫ Rax50 Firmware Version < 1.0.2.72
Netgear ≫ Rax75 Firmware Version < 1.0.3.106
Netgear ≫ Rax80 Firmware Version < 1.0.3.106
Netgear ≫ Rax200 Firmware Version < 1.0.3.106
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.239 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.4 | 1.7 | 6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 5.2 | 5.1 | 6.4 |
AV:A/AC:L/Au:S/C:P/I:P/A:P
|
cve@mitre.org | 7.6 | 1 | 6 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.