PT-2020-13392 · NetGear · Netgear R7800+15
Dieter Vymazal
+4
·
Published
2020-05-28
·
Updated
2020-05-29
·
CVE-2020-13245
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR R7000 versions 1.0.9.6 1.2.19 through 1.0.11.100 10.2.10
NETGEAR R6120 (affected versions not specified)
NETGEAR R7800 (affected versions not specified)
NETGEAR R6220 (affected versions not specified)
NETGEAR R8000 (affected versions not specified)
NETGEAR R6350 (affected versions not specified)
NETGEAR R9000 (affected versions not specified)
NETGEAR R6400 (affected versions not specified)
NETGEAR RAX120 (affected versions not specified)
NETGEAR R6400v2 (affected versions not specified)
NETGEAR RBR20 (affected versions not specified)
NETGEAR R6800 (affected versions not specified)
NETGEAR XR300 (affected versions not specified)
NETGEAR R6850 (affected versions not specified)
NETGEAR XR500 (affected versions not specified)
NETGEAR R7000P (affected versions not specified)
Description
The issue is related to Missing SSL Certificate Validation, which affects certain NETGEAR devices.
Recommendations
For NETGEAR R7000 versions 1.0.9.6 1.2.19 through 1.0.11.100 10.2.10, update to a version outside of this range to resolve the issue.
For NETGEAR R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R6120
Netgear R6220
Netgear R6350
Netgear R6400
Netgear R6400V2
Netgear R6800
Netgear R6850
Netgear R7000
Netgear R7000P
Netgear R7800
Netgear R8000
Netgear R9000
Netgear Rax120
Netgear Rbr20
Netgear Xr300
Netgear Xr500