PT-2020-10723 · NetGear · Rbr50+10
Aircut
·
Published
2020-04-16
·
Updated
2020-04-21
·
CVE-2019-20748
CVSS v3.1
6.8
Medium
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:H/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR D7800 versions 1.0.1.44 and earlier
NETGEAR R7500v2 versions 1.0.3.38 and earlier
NETGEAR R7800 versions 1.0.2.52 and earlier
NETGEAR RBK20 versions 2.3.0.28 and earlier
NETGEAR RBR20 versions 2.3.0.28 and earlier
NETGEAR RBS20 versions 2.3.0.28 and earlier
NETGEAR RBK40 versions 2.3.0.28 and earlier
NETGEAR RBS40 versions 2.3.0.28 and earlier
NETGEAR RBK50 versions 2.3.0.32 and earlier
NETGEAR RBR50 versions 2.3.0.32 and earlier
NETGEAR RBS50 versions 2.3.0.32 and earlier
Description
A stack-based buffer overflow issue affects certain NETGEAR devices, allowing an authenticated user to potentially exploit this issue.
Recommendations
For D7800 version 1.0.1.44 and earlier, update to version 1.0.1.44 or later.
For R7500v2 version 1.0.3.38 and earlier, update to version 1.0.3.38 or later.
For R7800 version 1.0.2.52 and earlier, update to version 1.0.2.52 or later.
For RBK20 version 2.3.0.28 and earlier, update to version 2.3.0.28 or later.
For RBR20 version 2.3.0.28 and earlier, update to version 2.3.0.28 or later.
For RBS20 version 2.3.0.28 and earlier, update to version 2.3.0.28 or later.
For RBK40 version 2.3.0.28 and earlier, update to version 2.3.0.28 or later.
For RBS40 version 2.3.0.28 and earlier, update to version 2.3.0.28 or later.
For RBK50 version 2.3.0.32 and earlier, update to version 2.3.0.32 or later.
For RBR50 version 2.3.0.32 and earlier, update to version 2.3.0.32 or later.
For RBS50 version 2.3.0.32 and earlier, update to version 2.3.0.32 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D7800
R7500V2
R7800
Rbk20
Rbk40
Rbk50
Rbr20
Rbr50
Rbs20
Rbs40
Rbs50