PT-2020-8807 · NetGear · Ex3800+18

Mongo

·

Published

2020-04-23

·

Updated

2020-05-01

·

CVE-2018-21163

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DGN2200Bv4 versions 1.0.0.0 through 1.0.0.101 DGN2200v4 versions 1.0.0.0 through 1.0.0.101 EX3700 versions 1.0.0.0 through 1.0.0.69 EX3800 versions 1.0.0.0 through 1.0.0.69 EX6000 versions 1.0.0.0 through 1.0.0.29 EX6100 versions 1.0.0.0 through 1.0.2.21 EX6120 versions 1.0.0.0 through 1.0.0.39 EX6130 versions 1.0.0.0 through 1.0.0.21 EX6150 versions 1.0.0.0 through 1.0.0.37 EX6200 versions 1.0.0.0 through 1.0.3.85 EX7000 versions 1.0.0.0 through 1.0.0.63 R6300v2 versions 1.0.0.0 through 1.0.4.21 R6900P versions 1.0.0.0 through 1.3.0.17 R7000P versions 1.0.0.0 through 1.3.0.17 R7300DST versions 1.0.0.0 through 1.0.0.61 R7900P versions 1.0.0.0 through 1.3.0.9 R8000 versions 1.0.0.0 through 1.0.4.11 R8000P versions 1.0.0.0 through 1.3.0.9 WN2500RPv2 versions 1.0.0.0 through 1.0.1.51 WNDR3400v3 versions 1.0.0.0 through 1.0.1.17
Description The issue is a stack-based buffer overflow that can be exploited by an authenticated user. This allows for potential unauthorized access and control.
Recommendations For DGN2200Bv4 versions 1.0.0.0 through 1.0.0.101, update to version 1.0.0.102 or later. For DGN2200v4 versions 1.0.0.0 through 1.0.0.101, update to version 1.0.0.102 or later. For EX3700 versions 1.0.0.0 through 1.0.0.69, update to version 1.0.0.70 or later. For EX3800 versions 1.0.0.0 through 1.0.0.69, update to version 1.0.0.70 or later. For EX6000 versions 1.0.0.0 through 1.0.0.29, update to version 1.0.0.30 or later. For EX6100 versions 1.0.0.0 through 1.0.2.21, update to version 1.0.2.22 or later. For EX6120 versions 1.0.0.0 through 1.0.0.39, update to version 1.0.0.40 or later. For EX6130 versions 1.0.0.0 through 1.0.0.21, update to version 1.0.0.22 or later. For EX6150 versions 1.0.0.0 through 1.0.0.37, update to version 1.0.0.38 or later. For EX6200 versions 1.0.0.0 through 1.0.3.85, update to version 1.0.3.86 or later. For EX7000 versions 1.0.0.0 through 1.0.0.63, update to version 1.0.0.64 or later. For R6300v2 versions 1.0.0.0 through 1.0.4.21, update to version 1.0.4.22 or later. For R6900P versions 1.0.0.0 through 1.3.0.17, update to version 1.3.0.18 or later. For R7000P versions 1.0.0.0 through 1.3.0.17, update to version 1.3.0.18 or later. For R7300DST versions 1.0.0.0 through 1.0.0.61, update to version 1.0.0.62 or later. For R7900P versions 1.0.0.0 through 1.3.0.9, update to version 1.3.0.10 or later. For R8000 versions 1.0.0.0 through 1.0.4.11, update to version 1.0.4.12 or later. For R8000P versions 1.0.0.0 through 1.3.0.9, update to version 1.3.0.10 or later. For WN2500RPv2 versions 1.0.0.0 through 1.0.1.51, update to version 1.0.1.52 or later. For WNDR3400v3 versions 1.0.0.0 through 1.0.1.17, update to version 1.0.1.18 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21163

Affected Products

Dgn2200V4
Ex3700
Ex3800
Ex6000
Ex6100
Ex6120
Ex6130
Ex6150
Ex6200
Ex7000
R6300V2
R6900P
R7000P
R7300Dst
R7900P
R8000
R8000P
Wn2500Rpv2
Wndr3400V3