Lucene search

K
cvelistTwcertCVELIST:CVE-2022-21742
HistoryJun 20, 2022 - 5:30 a.m.

CVE-2022-21742 Realtek USB FE/1GbE/2.5GbE/5GbE NIC Family - Buffer Overflow

2022-06-2005:30:28
CWE-120
twcert
www.cve.org
2
realtek usb driver
buffer overflow
lan attacker
vulnerability

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

19.8%

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.

CNA Affected

[
  {
    "platforms": [
      "Windows 10"
    ],
    "product": "USB FE/1GbE/2.5GbE/5GbE NIC Family",
    "vendor": "Realtek",
    "versions": [
      {
        "lessThanOrEqual": "10.39",
        "status": "affected",
        "version": "10.28",
        "versionType": "custom"
      }
    ]
  },
  {
    "platforms": [
      "Windows 8"
    ],
    "product": "USB FE/1GbE/2.5GbE/5GbE NIC Family",
    "vendor": "Realtek",
    "versions": [
      {
        "lessThanOrEqual": "8.60",
        "status": "affected",
        "version": "8.49",
        "versionType": "custom"
      }
    ]
  },
  {
    "platforms": [
      "Windows 7"
    ],
    "product": "USB FE/1GbE/2.5GbE/5GbE NIC Family",
    "vendor": "Realtek",
    "versions": [
      {
        "lessThanOrEqual": "7.53",
        "status": "affected",
        "version": "7.42",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

19.8%

Related for CVELIST:CVE-2022-21742