PT-2020-8737 · NetGear · Ex3800+30

Aircut

·

Published

2020-04-27

·

Updated

2020-05-04

·

CVE-2018-21093

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D8500 versions 1.0.3.42 and earlier EX3700 versions 1.0.0.70 and earlier EX3800 versions 1.0.0.70 and earlier EX6000 versions 1.0.0.30 and earlier EX6100 versions 1.0.2.24 and earlier EX6120 versions 1.0.0.40 and earlier EX6130 versions 1.0.0.22 and earlier EX6150 versions 1.0.0.42 and earlier EX6200 versions 1.0.3.88 and earlier EX7000 versions 1.0.0.66 and earlier R6250 versions 1.0.4.26 and earlier R6300-2CXNAS versions 1.0.3.60 and earlier R6300v2 versions 1.0.4.28 and earlier R6400 versions 1.0.1.36 and earlier R6400v2 versions 1.0.2.52 and earlier R6700 versions 1.0.1.46 and earlier R6900 versions 1.0.1.46 and earlier R7000 versions 1.0.9.28 and earlier R7000P versions 1.3.1.44 and earlier R6900P versions 1.3.1.44 and earlier R7100LG versions 1.0.0.46 and earlier R7300 versions 1.0.0.68 and earlier R7900 versions 1.0.2.10 and earlier R8000 versions 1.0.4.18 and earlier R8000P versions 1.3.0.10 and earlier R7900P versions 1.3.0.10 and earlier R8500 versions 1.0.2.122 and earlier R8300 versions 1.0.2.122 and earlier RBW30 versions 2.1.2.6 and earlier WN2500RPv2 versions 1.0.0.54 and earlier WNR3500Lv2 versions 1.2.0.56 and earlier
Description The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations Update D8500 to version 1.0.3.42 or later. Update EX3700 to version 1.0.0.70 or later. Update EX3800 to version 1.0.0.70 or later. Update EX6000 to version 1.0.0.30 or later. Update EX6100 to version 1.0.2.24 or later. Update EX6120 to version 1.0.0.40 or later. Update EX6130 to version 1.0.0.22 or later. Update EX6150 to version 1.0.0.42 or later. Update EX6200 to version 1.0.3.88 or later. Update EX7000 to version 1.0.0.66 or later. Update R6250 to version 1.0.4.26 or later. Update R6300-2CXNAS to version 1.0.3.60 or later. Update R6300v2 to version 1.0.4.28 or later. Update R6400 to version 1.0.1.36 or later. Update R6400v2 to version 1.0.2.52 or later. Update R6700 to version 1.0.1.46 or later. Update R6900 to version 1.0.1.46 or later. Update R7000 to version 1.0.9.28 or later. Update R7000P to version 1.3.1.44 or later. Update R6900P to version 1.3.1.44 or later. Update R7100LG to version 1.0.0.46 or later. Update R7300 to version 1.0.0.68 or later. Update R7900 to version 1.0.2.10 or later. Update R8000 to version 1.0.4.18 or later. Update R8000P to version 1.3.0.10 or later. Update R7900P to version 1.3.0.10 or later. Update R8500 to version 1.0.2.122 or later. Update R8300 to version 1.0.2.122 or later. Update RBW30 to version 2.1.2.6 or later. Update WN2500RPv2 to version 1.0.0.54 or later. Update WNR3500Lv2 to version 1.2.0.56 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21093

Affected Products

D8500
Ex3700
Ex3800
Ex6000
Ex6100
Ex6120
Ex6130
Ex6150
Ex6200
Ex7000
R6250
R6300-2Cxnas
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7100Lg
R7300
R7900
R7900P
R8000
R8000P
R8300
R8500
Rbw30
Wn2500Rpv2
Wnr3500Lv2