Lucene search

K
nvd[email protected]NVD:CVE-2019-20740
HistoryApr 16, 2020 - 8:15 p.m.

CVE-2019-20740

2020-04-1620:15:13
CWE-787
web.nvd.nist.gov
5

CVSS2

5.2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R7300 before 1.0.0.70, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

Affected configurations

Nvd
Node
netgeardgn2200_firmwareRange<1.0.0.110
AND
netgeardgn2200Matchv4
Node
netgeardgnd2200b_firmwareRange<1.0.0.109
AND
netgeardgnd2200bMatchv4
Node
netgearr7300_firmwareRange<1.0.0.70
AND
netgearr7300Match-
Node
netgearr8300_firmwareRange<1.0.2.130
AND
netgearr8300Match-
Node
netgearr8500_firmwareRange<1.0.2.130
AND
netgearr8500Match-
VendorProductVersionCPE
netgeardgn2200_firmware*cpe:2.3:o:netgear:dgn2200_firmware:*:*:*:*:*:*:*:*
netgeardgn2200v4cpe:2.3:h:netgear:dgn2200:v4:*:*:*:*:*:*:*
netgeardgnd2200b_firmware*cpe:2.3:o:netgear:dgnd2200b_firmware:*:*:*:*:*:*:*:*
netgeardgnd2200bv4cpe:2.3:h:netgear:dgnd2200b:v4:*:*:*:*:*:*:*
netgearr7300_firmware*cpe:2.3:o:netgear:r7300_firmware:*:*:*:*:*:*:*:*
netgearr7300-cpe:2.3:h:netgear:r7300:-:*:*:*:*:*:*:*
netgearr8300_firmware*cpe:2.3:o:netgear:r8300_firmware:*:*:*:*:*:*:*:*
netgearr8300-cpe:2.3:h:netgear:r8300:-:*:*:*:*:*:*:*
netgearr8500_firmware*cpe:2.3:o:netgear:r8500_firmware:*:*:*:*:*:*:*:*
netgearr8500-cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*

CVSS2

5.2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2019-20740