PT-2020-8807 · NetGear · Ex3800+18
Mongo
·
Published
2020-04-23
·
Updated
2020-05-01
·
CVE-2018-21163
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DGN2200Bv4 versions 1.0.0.0 through 1.0.0.101
DGN2200v4 versions 1.0.0.0 through 1.0.0.101
EX3700 versions 1.0.0.0 through 1.0.0.69
EX3800 versions 1.0.0.0 through 1.0.0.69
EX6000 versions 1.0.0.0 through 1.0.0.29
EX6100 versions 1.0.0.0 through 1.0.2.21
EX6120 versions 1.0.0.0 through 1.0.0.39
EX6130 versions 1.0.0.0 through 1.0.0.21
EX6150 versions 1.0.0.0 through 1.0.0.37
EX6200 versions 1.0.0.0 through 1.0.3.85
EX7000 versions 1.0.0.0 through 1.0.0.63
R6300v2 versions 1.0.0.0 through 1.0.4.21
R6900P versions 1.0.0.0 through 1.3.0.17
R7000P versions 1.0.0.0 through 1.3.0.17
R7300DST versions 1.0.0.0 through 1.0.0.61
R7900P versions 1.0.0.0 through 1.3.0.9
R8000 versions 1.0.0.0 through 1.0.4.11
R8000P versions 1.0.0.0 through 1.3.0.9
WN2500RPv2 versions 1.0.0.0 through 1.0.1.51
WNDR3400v3 versions 1.0.0.0 through 1.0.1.17
Description
The issue is a stack-based buffer overflow that can be exploited by an authenticated user. This allows for potential unauthorized access and control.
Recommendations
For DGN2200Bv4 versions 1.0.0.0 through 1.0.0.101, update to version 1.0.0.102 or later.
For DGN2200v4 versions 1.0.0.0 through 1.0.0.101, update to version 1.0.0.102 or later.
For EX3700 versions 1.0.0.0 through 1.0.0.69, update to version 1.0.0.70 or later.
For EX3800 versions 1.0.0.0 through 1.0.0.69, update to version 1.0.0.70 or later.
For EX6000 versions 1.0.0.0 through 1.0.0.29, update to version 1.0.0.30 or later.
For EX6100 versions 1.0.0.0 through 1.0.2.21, update to version 1.0.2.22 or later.
For EX6120 versions 1.0.0.0 through 1.0.0.39, update to version 1.0.0.40 or later.
For EX6130 versions 1.0.0.0 through 1.0.0.21, update to version 1.0.0.22 or later.
For EX6150 versions 1.0.0.0 through 1.0.0.37, update to version 1.0.0.38 or later.
For EX6200 versions 1.0.0.0 through 1.0.3.85, update to version 1.0.3.86 or later.
For EX7000 versions 1.0.0.0 through 1.0.0.63, update to version 1.0.0.64 or later.
For R6300v2 versions 1.0.0.0 through 1.0.4.21, update to version 1.0.4.22 or later.
For R6900P versions 1.0.0.0 through 1.3.0.17, update to version 1.3.0.18 or later.
For R7000P versions 1.0.0.0 through 1.3.0.17, update to version 1.3.0.18 or later.
For R7300DST versions 1.0.0.0 through 1.0.0.61, update to version 1.0.0.62 or later.
For R7900P versions 1.0.0.0 through 1.3.0.9, update to version 1.3.0.10 or later.
For R8000 versions 1.0.0.0 through 1.0.4.11, update to version 1.0.4.12 or later.
For R8000P versions 1.0.0.0 through 1.3.0.9, update to version 1.3.0.10 or later.
For WN2500RPv2 versions 1.0.0.0 through 1.0.1.51, update to version 1.0.1.52 or later.
For WNDR3400v3 versions 1.0.0.0 through 1.0.1.17, update to version 1.0.1.18 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dgn2200V4
Ex3700
Ex3800
Ex6000
Ex6100
Ex6120
Ex6130
Ex6150
Ex6200
Ex7000
R6300V2
R6900P
R7000P
R7300Dst
R7900P
R8000
R8000P
Wn2500Rpv2
Wndr3400V3