ID

VAR-200609-0169


CVE

CVE-2006-4765


TITLE

NetGear Denial of Service Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2006-7038 // CNNVD: CNNVD-200609-190

DESCRIPTION

NETGEAR DG834GT Wireless ADSL router running firmware 1.01.28 allows attackers to cause a denial of service (device hang) via a long string in the username field in the login window. The NetGear DG834GT device is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input. This issue allows attackers to cause the device to stop responding to network requests, effectively denying service to legitimate users

Trust: 2.52

sources: NVD: CVE-2006-4765 // JVNDB: JVNDB-2006-002102 // CNVD: CNVD-2006-7038 // BID: 19973 // VULHUB: VHN-20873

AFFECTED PRODUCTS

vendor:netgearmodel:dg834gtscope:eqversion:1.01.28

Trust: 1.6

vendor:net gearmodel:dg834gtscope:eqversion:firmware 1.01.28

Trust: 0.8

vendor:dg834gtmodel:netgearscope:eqversion:1.01.28

Trust: 0.6

vendor:netgearmodel:dg834gt wireless adsl routerscope:eqversion:v1.01.28

Trust: 0.3

sources: CNVD: CNVD-2006-7038 // BID: 19973 // JVNDB: JVNDB-2006-002102 // CNNVD: CNNVD-200609-190 // NVD: CVE-2006-4765

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-4765
value: MEDIUM

Trust: 1.0

NVD: CVE-2006-4765
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2006-7038
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-200609-190
value: MEDIUM

Trust: 0.6

VULHUB: VHN-20873
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2006-4765
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2006-7038
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-20873
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2006-7038 // VULHUB: VHN-20873 // JVNDB: JVNDB-2006-002102 // CNNVD: CNNVD-200609-190 // NVD: CVE-2006-4765

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-4765

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200609-190

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200609-190

CONFIGURATIONS

sources: JVNDB: JVNDB-2006-002102

PATCH

title:Top Pageurl:http://www.netgear.com/

Trust: 0.8

sources: JVNDB: JVNDB-2006-002102

EXTERNAL IDS

db:NVDid:CVE-2006-4765

Trust: 3.1

db:BIDid:19973

Trust: 2.6

db:SREASONid:1575

Trust: 1.7

db:JVNDBid:JVNDB-2006-002102

Trust: 0.8

db:CNNVDid:CNNVD-200609-190

Trust: 0.7

db:CNVDid:CNVD-2006-7038

Trust: 0.6

db:BUGTRAQid:20060912 NETGEAR ROTUER DG834GT FIRMWARE V1.01.28 (DOS)

Trust: 0.6

db:XFid:28902

Trust: 0.6

db:VULHUBid:VHN-20873

Trust: 0.1

sources: CNVD: CNVD-2006-7038 // VULHUB: VHN-20873 // BID: 19973 // JVNDB: JVNDB-2006-002102 // CNNVD: CNNVD-200609-190 // NVD: CVE-2006-4765

REFERENCES

url:http://www.securityfocus.com/bid/19973

Trust: 2.3

url:http://securityreason.com/securityalert/1575

Trust: 1.7

url:http://www.securityfocus.com/archive/1/445819/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/28902

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-4765

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2006-4765

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/445819/100/0/threaded

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/28902

Trust: 0.6

url:http://www.netgear.com/

Trust: 0.3

url:http://www.netgear.com/products/routersandgateways/agdualbandwirelessrouters/dg834gt.aspx

Trust: 0.3

sources: CNVD: CNVD-2006-7038 // VULHUB: VHN-20873 // BID: 19973 // JVNDB: JVNDB-2006-002102 // CNNVD: CNNVD-200609-190 // NVD: CVE-2006-4765

CREDITS

NullFlag is credited with the discovery of this vulnerability.

Trust: 0.9

sources: BID: 19973 // CNNVD: CNNVD-200609-190

SOURCES

db:CNVDid:CNVD-2006-7038
db:VULHUBid:VHN-20873
db:BIDid:19973
db:JVNDBid:JVNDB-2006-002102
db:CNNVDid:CNNVD-200609-190
db:NVDid:CVE-2006-4765

LAST UPDATE DATE

2024-08-14T13:39:35.531000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2006-7038date:2006-09-13T00:00:00
db:VULHUBid:VHN-20873date:2018-10-17T00:00:00
db:BIDid:19973date:2006-09-13T16:32:00
db:JVNDBid:JVNDB-2006-002102date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200609-190date:2006-09-18T00:00:00
db:NVDid:CVE-2006-4765date:2018-10-17T21:39:29.043

SOURCES RELEASE DATE

db:CNVDid:CNVD-2006-7038date:2006-09-13T00:00:00
db:VULHUBid:VHN-20873date:2006-09-13T00:00:00
db:BIDid:19973date:2006-09-12T00:00:00
db:JVNDBid:JVNDB-2006-002102date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200609-190date:2006-09-13T00:00:00
db:NVDid:CVE-2006-4765date:2006-09-13T23:07:00