ID

VAR-200304-0139


TITLE

Netgear FM114P ProSafe Wireless Router Rules Can Be Vulnerable

Trust: 0.6

sources: CNVD: CNVD-2003-0957

DESCRIPTION

Netgear FM114P ProSafe is a wireless network router. The Netgear FM114P ProSafe wireless network router uses a port blocking rule vulnerability when using the UPnP feature, which can be exploited by remote attackers to bypass restricted access to restricted ports. Netgear FM114P allows blocking of some ports, restricting external users from accessing the internal network or restricting internal users from connecting to the WAN. If remote access and UPnP functions are enabled in the device, remote users can submit UPnP SOAP request connections to bypass rule access restrictions. port,

Trust: 0.81

sources: CNVD: CNVD-2003-0957 // BID: 7270

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2003-0957

AFFECTED PRODUCTS

vendor:netgearmodel:fwag114 1.0.26rc4scope: - version: -

Trust: 0.6

vendor:netgearmodel:fm114pscope: - version: -

Trust: 0.3

sources: CNVD: CNVD-2003-0957 // BID: 7270

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2003-0957
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2003-0957
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2003-0957

THREAT TYPE

network

Trust: 0.3

sources: BID: 7270

TYPE

Configuration Error

Trust: 0.3

sources: BID: 7270

EXTERNAL IDS

db:BIDid:7270

Trust: 0.9

db:CNVDid:CNVD-2003-0957

Trust: 0.6

sources: CNVD: CNVD-2003-0957 // BID: 7270

REFERENCES

url:http://marc.theaimsgroup.com/?l=bugtraq&m=104940758020372&w=2

Trust: 0.6

url:/archive/1/317358

Trust: 0.3

sources: CNVD: CNVD-2003-0957 // BID: 7270

CREDITS

Discovery is credited to Björn Stickler <stickler@rbg.informatik.tu-darmstadt.de>.

Trust: 0.3

sources: BID: 7270

SOURCES

db:CNVDid:CNVD-2003-0957
db:BIDid:7270

LAST UPDATE DATE

2022-05-17T02:06:53.627000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-0957date:2003-04-03T00:00:00
db:BIDid:7270date:2003-04-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-0957date:2003-04-03T00:00:00
db:BIDid:7270date:2003-04-03T00:00:00