PT-2020-10698 · NetGear · Xr500+21

Aircut

·

Published

2020-04-16

·

Updated

2020-04-22

·

CVE-2019-20723

CVSS v3.1

6.8

Medium

VectorAC:L/AV:A/A:H/C:H/I:H/PR:H/S:U/UI:N
Name of the Vulnerable Software and Affected Versions D3600 versions 1.0.0.0 through 1.0.0.74 D6000 versions 1.0.0.0 through 1.0.0.74 D6100 versions 1.0.0.0 through 1.0.0.62 DM200 versions 1.0.0.0 through 1.0.0.57 EX2700 versions 1.0.0.0 through 1.0.1.47 EX6100v2 versions 1.0.0.0 through 1.0.1.75 EX6150v2 versions 1.0.0.0 through 1.0.1.75 EX6200v2 versions 1.0.0.0 through 1.0.1.71 EX6400 versions 1.0.0.0 through 1.0.2.135 EX7300 versions 1.0.0.0 through 1.0.2.135 EX8000 versions 1.0.0.0 through 1.0.1.179 R7800 versions 1.0.0.0 through 1.0.2.51 R8900 versions 1.0.0.0 through 1.0.4.1 R9000 versions 1.0.0.0 through 1.0.4.1 WN2000RPTv3 versions 1.0.0.0 through 1.0.1.31 WN3000RPv2 versions 1.0.0.0 through 1.0.0.67 WN3000RPv3 versions 1.0.0.0 through 1.0.2.69 WN3100RPv2 versions 1.0.0.0 through 1.0.0.59 WNDR4300v2 versions 1.0.0.0 through 1.0.0.57 WNDR4500v3 versions 1.0.0.0 through 1.0.0.57 WNR2000v5 versions 1.0.0.0 through 1.0.0.67 XR500 versions 1.0.0.0 through 2.3.2.31
Description A stack-based buffer overflow issue affects certain NETGEAR devices, allowing an authenticated user to potentially exploit this issue.
Recommendations D3600 versions 1.0.0.0 through 1.0.0.74: Update to version 1.0.0.75 or later. D6000 versions 1.0.0.0 through 1.0.0.74: Update to version 1.0.0.75 or later. D6100 versions 1.0.0.0 through 1.0.0.62: Update to version 1.0.0.63 or later. DM200 versions 1.0.0.0 through 1.0.0.57: Update to version 1.0.0.58 or later. EX2700 versions 1.0.0.0 through 1.0.1.47: Update to version 1.0.1.48 or later. EX6100v2 versions 1.0.0.0 through 1.0.1.75: Update to version 1.0.1.76 or later. EX6150v2 versions 1.0.0.0 through 1.0.1.75: Update to version 1.0.1.76 or later. EX6200v2 versions 1.0.0.0 through 1.0.1.71: Update to version 1.0.1.72 or later. EX6400 versions 1.0.0.0 through 1.0.2.135: Update to version 1.0.2.136 or later. EX7300 versions 1.0.0.0 through 1.0.2.135: Update to version 1.0.2.136 or later. EX8000 versions 1.0.0.0 through 1.0.1.179: Update to version 1.0.1.180 or later. R7800 versions 1.0.0.0 through 1.0.2.51: Update to version 1.0.2.52 or later. R8900 versions 1.0.0.0 through 1.0.4.1: Update to version 1.0.4.2 or later. R9000 versions 1.0.0.0 through 1.0.4.1: Update to version 1.0.4.2 or later. WN2000RPTv3 versions 1.0.0.0 through 1.0.1.31: Update to version 1.0.1.32 or later. WN3000RPv2 versions 1.0.0.0 through 1.0.0.67: Update to version 1.0.0.68 or later. WN3000RPv3 versions 1.0.0.0 through 1.0.2.69: Update to version 1.0.2.70 or later. WN3100RPv2 versions 1.0.0.0 through 1.0.0.59: Update to version 1.0.0.60 or later. WNDR4300v2 versions 1.0.0.0 through 1.0.0.57: Update to version 1.0.0.58 or later. WNDR4500v3 versions 1.0.0.0 through 1.0.0.57: Update to version 1.0.0.58 or later. WNR2000v5 versions 1.0.0.0 through 1.0.0.67: Update to version 1.0.0.68 or later. XR500 versions 1.0.0.0 through 2.3.2.31: Update to version 2.3.2.32 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20723

Affected Products

D3600
D6000
D6100
Dm200
Ex2700
Ex6100V2
Ex6150V2
Ex6200V2
Ex6400
Ex7300
Ex8000
R7800
R8900
R9000
Wn2000Rptv3
Wn3000Rpv2
Wn3000Rpv3
Wn3100Rpv2
Wndr4300V2
Wndr4500V3
Wnr2000V5
Xr500