PT-2021-5871 · NetGear · Ex6120+47

Published

2021-09-25

·

Updated

2022-01-12

·

CVE-2021-45641

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D3600 versions 1.0.0.0 through 1.0.0.71 D6000 versions 1.0.0.0 through 1.0.0.71 D6200 versions 1.0.0.0 through 1.1.00.33 D6220 versions 1.0.0.0 through 1.0.0.51 D6400 versions 1.0.0.0 through 1.0.0.85 D7000 versions 1.0.0.0 through 1.0.1.73 D7000v2 versions 1.0.0.0 through 1.0.0.52 D7800 versions 1.0.0.0 through 1.0.1.55 D8500 versions 1.0.0.0 through 1.0.3.43 DC112A versions 1.0.0.0 through 1.0.0.41 DGN2200Bv4 versions 1.0.0.0 through 1.0.0.108 DGN2200v4 versions 1.0.0.0 through 1.0.0.109 DM200 versions 1.0.0.0 through 1.0.0.60 EX3700 versions 1.0.0.0 through 1.0.0.75 EX3800 versions 1.0.0.0 through 1.0.0.75 EX6120 versions 1.0.0.0 through 1.0.0.45 EX6130 versions 1.0.0.0 through 1.0.0.27 EX7000 versions 1.0.0.0 through 1.0.1.77 PR2000 versions 1.0.0.0 through 1.0.0.27 R6220 versions 1.0.0.0 through 1.1.0.99 R6230 versions 1.0.0.0 through 1.1.0.99 R6250 versions 1.0.0.0 through 1.0.4.33 R6300v2 versions 1.0.0.0 through 1.0.4.33 R6400 versions 1.0.0.0 through 1.0.1.45 R6400v2 versions 1.0.0.0 through 1.0.2.65 R6700 versions 1.0.0.0 through 1.0.2.5 R6700v3 versions 1.0.0.0 through 1.0.2.65 R6900 versions 1.0.0.0 through 1.0.2.5 R7000 versions 1.0.0.0 through 1.0.9.33 R7100LG versions 1.0.0.0 through 1.0.0.49 R7500v2 versions 1.0.0.0 through 1.0.3.39 R7900P versions 1.0.0.0 through 1.4.1.49 R8000P versions 1.0.0.0 through 1.4.1.49 R8900 versions 1.0.0.0 through 1.0.4.11 R9000 versions 1.0.0.0 through 1.0.4.11 RBK20 versions 2.0.0.0 through 2.3.0.27 RBR20 versions 2.0.0.0 through 2.3.0.27 RBS20 versions 2.0.0.0 through 2.3.0.27 RBK40 versions 2.0.0.0 through 2.3.0.27 RBR40 versions 2.0.0.0 through 2.3.0.27 RBS40 versions 2.0.0.0 through 2.3.0.27 RBK50 versions 2.0.0.0 through 2.3.0.31 RBR50 versions 2.0.0.0 through 2.3.0.31 RBS50 versions 2.0.0.0 through 2.3.0.31 WN3000RPv2 versions 1.0.0.0 through 1.0.0.77 WNDR3400v3 versions 1.0.0.0 through 1.0.1.23 WNR2000v5 versions 1.0.0.0 through 1.0.0.69 WNR2020 versions 1.0.0.0 through 1.1.0.61 XR500 versions 2.0.0.0 through 2.3.2.55
Description The issue is related to the incorrect configuration of security settings in certain NETGEAR devices. This may allow a remote attacker to impact the integrity and availability of protected information. The vulnerability is associated with insufficient protection of service data.
Recommendations Update D3600 to version 1.0.0.72 or later Update D6000 to version 1.0.0.72 or later Update D6200 to version 1.1.00.34 or later Update D6220 to version 1.0.0.52 or later Update D6400 to version 1.0.0.86 or later Update D7000 to version 1.0.1.74 or later Update D7000v2 to version 1.0.0.53 or later Update D7800 to version 1.0.1.56 or later Update D8500 to version 1.0.3.44 or later Update DC112A to version 1.0.0.42 or later Update DGN2200Bv4 to version 1.0.0.109 or later Update DGN2200v4 to version 1.0.0.110 or later Update DM200 to version 1.0.0.61 or later Update EX3700 to version 1.0.0.76 or later Update EX3800 to version 1.0.0.76 or later Update EX6120 to version 1.0.0.46 or later Update EX6130 to version 1.0.0.28 or later Update EX7000 to version 1.0.1.78 or later Update PR2000 to version 1.0.0.28 or later Update R6220 to version 1.1.0.100 or later Update R6230 to version 1.1.0.100 or later Update R6250 to version 1.0.4.34 or later Update R6300v2 to version 1.0.4.34 or later Update R6400 to version 1.0.1.46 or later Update R6400v2 to version 1.0.2.66 or later Update R6700 to version 1.0.2.6 or later Update R6700v3 to version 1.0.2.66 or later Update R6900 to version 1.0.2.6 or later Update R7000 to version 1.0.9.34 or later Update R7100LG to version 1.0.0.50 or later Update R7500v2 to version 1.0.3.40 or later Update R7900P to version 1.4.1.50 or later Update R8000P to version 1.4.1.50 or later Update R8900 to version 1.0.4.12 or later Update R9000 to version 1.0.4.12 or later Update RBK20 to version 2.3.0.28 or later Update RBR20 to version 2.3.0.28 or later Update RBS20 to version 2.3.0.28 or later Update RBK40 to version 2.3.0.28 or later Update RBR40 to version 2.3.0.28 or later Update RBS40 to version 2.3.0.28 or later Update RBK50 to version 2.3.0.32 or later Update RBR50 to version 2.3.0.32 or later Update RBS50 to version 2.3.0.32 or later Update WN3000RPv2 to version 1.0.0.78 or later Update WNDR3400v3 to version 1.0.1.24 or later Update WNR2000v5 to version 1.0.0.70 or later Update WNR2020 to version 1.1.0.62 or later Update XR500 to version 2.3.2.56 or later

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00386
CVE-2021-45641

Affected Products

D3600
D6000
D6200
D6220
D6400
D7000
D7000V2
D7800
D8500
Dc112A
Dgn2200V4
Dm200
Ex3700
Ex3800
Ex6120
Ex6130
Ex7000
Pr2000
R6220
R6230
R6250
R6300V2
R6400
R6400V2
R6700
R6700V3
R6900
R7000
R7100Lg
R7500V2
R7900P
R8000P
R8900
R9000
Rbk20
Rbk40
Rbk50
Rbr20
Rbr40
Rbr50
Rbs20
Rbs40
Rbs50
Wn3000Rpv2
Wndr3400V3
Wnr2000V5
Wnr2020
Xr500