7.8
CVE-2021-41788
- EPSS 1.76%
- Veröffentlicht 26.12.2021 00:15:10
- Zuletzt bearbeitet 21.11.2024 06:26:45
- Erkennungen
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Mt7603e Firmware Version 7.4.0.0
Mediatek ≫ Mt7612 Firmware Version 7.4.0.0
Mediatek ≫ Mt7613 Firmware Version 7.4.0.0
Mediatek ≫ Mt7615 Firmware Version 7.4.0.0
Mediatek ≫ Mt7622 Firmware Version 7.4.0.0
Mediatek ≫ Mt7628 Firmware Version 7.4.0.0
Mediatek ≫ Mt7629 Firmware Version 7.4.0.0
Mediatek ≫ Mt7915 Firmware Version 7.4.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.76% | 0.755 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
| MITRE | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://corp.mediatek.com/product-security-bulletin/January-2022
https://kb.netgear.com/000064369/Security-Advisory-for-WiFi-Authentication-Flooding-Vulnerabilities-on-Multiple-Products-PSV-2021-0299-PSV-2021-0301