7.5

CVE-2021-45648

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6150v2 before 1.0.1.106, EX6250 before 1.0.0.146, EX6400 before 1.0.2.164, EX6400v2 before 1.0.0.146, EX6410 before 1.0.0.146, EX6420 before 1.0.0.146, EX7300 before 1.0.2.164, EX7300v2 before 1.0.0.146, EX7320 before 1.0.0.146, EX7700 before 1.0.0.222, LBR1020 before 2.6.5.16, LBR20 before 2.6.5.2, RBK352 before 4.3.4.7, RBK50 before 2.7.3.22, RBR350 before 4.3.4.7, RBR50 before 2.7.3.22, and RBS350 before 4.3.4.7.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetgearEx6100v2 Firmware Version < 1.0.1.106
   NetgearEx6100v2 Version-
NetgearEx6150v2 Firmware Version < 1.0.1.106
   NetgearEx6150v2 Version-
NetgearEx6250 Firmware Version < 1.0.0.146
   NetgearEx6250 Version-
NetgearEx6400 Firmware Version < 1.0.2.164
   NetgearEx6400 Version-
NetgearEx6400v2 Firmware Version < 1.0.0.146
   NetgearEx6400v2 Version-
NetgearEx6410 Firmware Version < 1.0.0.146
   NetgearEx6410 Version-
NetgearEx6420 Firmware Version < 1.0.0.146
   NetgearEx6420 Version-
NetgearEx7300 Firmware Version < 1.0.2.164
   NetgearEx7300 Version-
NetgearEx7300v2 Firmware Version < 1.0.0.146
   NetgearEx7300v2 Version-
NetgearEx7320 Firmware Version < 1.0.0.146
   NetgearEx7320 Version-
NetgearEx7700 Firmware Version < 1.0.0.222
   NetgearEx7700 Version-
NetgearLbr1020 Firmware Version < 2.6.5.16
   NetgearLbr1020 Version-
NetgearLbr20 Firmware Version < 2.6.5.2
   NetgearLbr20 Version-
NetgearRbk352 Firmware Version < 4.3.4.7
   NetgearRbk352 Version-
NetgearRbk50 Firmware Version < 2.7.3.22
   NetgearRbk50 Version-
NetgearRbr350 Firmware Version < 4.3.4.7
   NetgearRbr350 Version-
NetgearRbr50 Firmware Version < 2.7.3.22
   NetgearRbr50 Version-
NetgearRbs350 Firmware Version < 4.3.4.7
   NetgearRbs350 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.508
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
cve@mitre.org 3.1 1.6 1.4
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.