7.8

CVE-2021-41788

MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MediatekMt7603e Firmware Version7.4.0.0
   MediatekMt7603e Version-
MediatekMt7612 Firmware Version7.4.0.0
   MediatekMt7612 Version-
MediatekMt7613 Firmware Version7.4.0.0
   MediatekMt7613 Version-
MediatekMt7615 Firmware Version7.4.0.0
   MediatekMt7615 Version-
MediatekMt7622 Firmware Version7.4.0.0
   MediatekMt7622 Version-
MediatekMt7628 Firmware Version7.4.0.0
   MediatekMt7628 Version-
MediatekMt7629 Firmware Version7.4.0.0
   MediatekMt7629 Version-
MediatekMt7915 Firmware Version7.4.0.0
   MediatekMt7915 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.668
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
cve@mitre.org 6.5 2.2 4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.