4.9
CVE-2021-38524
- EPSS 0.29%
- Published 11.08.2021 00:16:04
- Last modified 21.11.2024 06:17:20
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX45 before 1.0.2.32, RAX50 before 1.0.2.32, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, and RBS750 before 3.2.16.6.
Data is provided by the National Vulnerability Database (NVD)
Netgear ≫ Mk62 Firmware Version < 1.0.6.110
Netgear ≫ Mr60 Firmware Version < 1.0.6.110
Netgear ≫ Ms60 Firmware Version < 1.0.6.110
Netgear ≫ Rax15 Firmware Version < 1.0.2.82
Netgear ≫ Rax20 Firmware Version < 1.0.2.82
Netgear ≫ Rax200 Firmware Version < 1.0.3.106
Netgear ≫ Rax45 Firmware Version < 1.0.2.32
Netgear ≫ Rax50 Firmware Version < 1.0.2.32
Netgear ≫ Rax75 Firmware Version < 1.0.3.106
Netgear ≫ Rax80 Firmware Version < 1.0.3.106
Netgear ≫ Rbk752 Firmware Version < 3.2.16.6
Netgear ≫ Rbr750 Firmware Version < 3.2.16.6
Netgear ≫ Rbs750 Firmware Version < 3.2.16.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.496 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
cve@mitre.org | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.