PT-2020-8800 · NetGear · Ex3700+32

Aircut

·

Published

2020-04-27

·

Updated

2020-05-05

·

CVE-2018-21156

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D6220 versions prior to 1.0.0.38 D6400 versions prior to 1.0.0.74 D7000v2 versions prior to 1.0.0.74 D8500 versions prior to 1.0.3.39 DGN2200v4 versions prior to 1.0.0.102 DGN2200Bv4 versions prior to 1.0.0.102 EX3700 versions prior to 1.0.0.70 EX3800 versions prior to 1.0.0.70 EX6000 versions prior to 1.0.0.30 EX6100 versions prior to 1.0.2.22 EX6120 versions prior to 1.0.0.40 EX6130 versions prior to 1.0.0.22 EX6150 versions prior to 1.0.0.38 EX6200 versions prior to 1.0.3.86 EX7000 versions prior to 1.0.0.64 R6250 versions prior to 1.0.4.20 R6300v2 versions prior to 1.0.4.22 R6400 versions prior to 1.0.1.32 R6400v2 versions prior to 1.0.2.52 R6700 versions prior to 1.0.1.44 R6900 versions prior to 1.0.1.44 R6900P versions prior to 1.3.0.18 R7000 versions prior to 1.0.9.28 R7000P versions prior to 1.3.0.18 R7300DST versions prior to 1.0.0.62 R7900 versions prior to 1.0.2.10 R7900P versions prior to 1.3.0.10 R8000 versions prior to 1.0.4.12 R8000P versions prior to 1.3.0.10 R8300 versions prior to 1.0.2.116 R8500 versions prior to 1.0.2.116 WN2500RPv2 versions prior to 1.0.1.52 WNDR3400v3 versions prior to 1.0.1.18 WNR3500Lv2 versions prior to 1.2.0.46
Description Certain NETGEAR devices are affected by a buffer overflow that can be triggered by an authenticated user.
Recommendations Update D6220 to version 1.0.0.38 or later. Update D6400 to version 1.0.0.74 or later. Update D7000v2 to version 1.0.0.74 or later. Update D8500 to version 1.0.3.39 or later. Update DGN2200v4 to version 1.0.0.102 or later. Update DGN2200Bv4 to version 1.0.0.102 or later. Update EX3700 to version 1.0.0.70 or later. Update EX3800 to version 1.0.0.70 or later. Update EX6000 to version 1.0.0.30 or later. Update EX6100 to version 1.0.2.22 or later. Update EX6120 to version 1.0.0.40 or later. Update EX6130 to version 1.0.0.22 or later. Update EX6150 to version 1.0.0.38 or later. Update EX6200 to version 1.0.3.86 or later. Update EX7000 to version 1.0.0.64 or later. Update R6250 to version 1.0.4.20 or later. Update R6300v2 to version 1.0.4.22 or later. Update R6400 to version 1.0.1.32 or later. Update R6400v2 to version 1.0.2.52 or later. Update R6700 to version 1.0.1.44 or later. Update R6900 to version 1.0.1.44 or later. Update R6900P to version 1.3.0.18 or later. Update R7000 to version 1.0.9.28 or later. Update R7000P to version 1.3.0.18 or later. Update R7300DST to version 1.0.0.62 or later. Update R7900 to version 1.0.2.10 or later. Update R7900P to version 1.3.0.10 or later. Update R8000 to version 1.0.4.12 or later. Update R8000P to version 1.3.0.10 or later. Update R8300 to version 1.0.2.116 or later. Update R8500 to version 1.0.2.116 or later. Update WN2500RPv2 to version 1.0.1.52 or later. Update WNDR3400v3 to version 1.0.1.18 or later. Update WNR3500Lv2 to version 1.2.0.46 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21156

Affected Products

D6220
D6400
D7000V2
D8500
Dgn2200V4
Ex3700
Ex3800
Ex6000
Ex6100
Ex6120
Ex6130
Ex6150
Ex6200
Ex7000
R6250
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7300Dst
R7900
R7900P
R8000
R8000P
R8300
R8500
Wn2500Rpv2
Wndr3400V3
Wnr3500Lv2