PT-2020-8296 · NetGear · Netgear Ex3800+7
Popeax
·
Published
2020-04-23
·
Updated
2020-04-23
·
CVE-2017-18747
CVSS v3.1
8.8
High
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions:
NETGEAR EX3700 versions prior to 1.0.0.64
NETGEAR EX3800 versions prior to 1.0.0.64
NETGEAR EX6000 versions prior to 1.0.0.24
NETGEAR EX6130 versions prior to 1.0.0.16
NETGEAR EX6400 versions prior to 1.0.1.60
NETGEAR EX7000 versions prior to 1.0.0.50
NETGEAR EX7300 versions prior to 1.0.1.60
NETGEAR WN2500RPv2 versions prior to 1.0.1.46
Description:
The issue is related to the incorrect configuration of security settings in certain NETGEAR devices.
Recommendations:
For NETGEAR EX3700 versions prior to 1.0.0.64, update to version 1.0.0.64 or later.
For NETGEAR EX3800 versions prior to 1.0.0.64, update to version 1.0.0.64 or later.
For NETGEAR EX6000 versions prior to 1.0.0.24, update to version 1.0.0.24 or later.
For NETGEAR EX6130 versions prior to 1.0.0.16, update to version 1.0.0.16 or later.
For NETGEAR EX6400 versions prior to 1.0.1.60, update to version 1.0.1.60 or later.
For NETGEAR EX7000 versions prior to 1.0.0.50, update to version 1.0.0.50 or later.
For NETGEAR EX7300 versions prior to 1.0.1.60, update to version 1.0.1.60 or later.
For NETGEAR WN2500RPv2 versions prior to 1.0.1.46, update to version 1.0.1.46 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Ex3700
Netgear Ex3800
Netgear Ex6000
Netgear Ex6130
Netgear Ex6400
Netgear Ex7000
Netgear Ex7300
Netgear Wn2500Rpv2