ID

VAR-202004-0764


CVE

CVE-2019-20702


TITLE

plural NETGEAR On the device OS Command injection vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2019-015330

DESCRIPTION

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32. NETGEAR D3600 , D6000 , XR500 On the device OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. NETGEAR D3600, etc. are all products of NETGEAR. NETGEAR D3600 is a wireless modem. NETGEAR D6000 is a wireless modem. NETGEAR XR500 is a wireless router. NETGEAR D3600 versions prior to 1.0.0.76, D6000 versions prior to 1.0.0.76 and XR500 versions prior to 2.3.2.32 have operating system command injection vulnerabilities. This vulnerability stems from the process of constructing operating system executable commands from external input data. By properly filtering the special characters and commands, the attacker can use the vulnerability to execute illegal operating system commands

Trust: 2.16

sources: NVD: CVE-2019-20702 // JVNDB: JVNDB-2019-015330 // CNVD: CNVD-2020-27257

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-27257

AFFECTED PRODUCTS

vendor:netgearmodel:xr500scope:ltversion:2.3.2.32

Trust: 1.6

vendor:netgearmodel:d3600scope:ltversion:1.0.0.76

Trust: 1.6

vendor:netgearmodel:d6000scope:ltversion:1.0.0.76

Trust: 1.6

vendor:netgearmodel:d3600scope:eqversion:1.0.0.76

Trust: 0.8

vendor:netgearmodel:d6000scope:eqversion:1.0.0.76

Trust: 0.8

vendor:netgearmodel:xr500scope:eqversion:2.3.2.32

Trust: 0.8

sources: CNVD: CNVD-2020-27257 // JVNDB: JVNDB-2019-015330 // NVD: CVE-2019-20702

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-20702
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2019-20702
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2019-015330
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-27257
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202004-1286
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-20702
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2019-015330
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-27257
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-20702
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2019-20702
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 4.2
version: 3.0

Trust: 1.0

NVD: JVNDB-2019-015330
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-27257 // JVNDB: JVNDB-2019-015330 // CNNVD: CNNVD-202004-1286 // NVD: CVE-2019-20702 // NVD: CVE-2019-20702

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:CWE-78

Trust: 0.8

sources: JVNDB: JVNDB-2019-015330 // NVD: CVE-2019-20702

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202004-1286

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-202004-1286

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-015330

PATCH

title:Security Advisory for Post-Authentication Command Injection on Some Routers and Gateways, PSV-2018-0394url:https://kb.netgear.com/000061227/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2018-0394

Trust: 0.8

title:Patch for NETGEAR D3600, D6000 and XR500 operating system command injection vulnerability (CNVD-2020-27257)url:https://www.cnvd.org.cn/patchInfo/show/216915

Trust: 0.6

title:NETGEAR D3600 , D6000 and XR500 Fixes for operating system command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116556

Trust: 0.6

sources: CNVD: CNVD-2020-27257 // JVNDB: JVNDB-2019-015330 // CNNVD: CNNVD-202004-1286

EXTERNAL IDS

db:NVDid:CVE-2019-20702

Trust: 3.0

db:JVNDBid:JVNDB-2019-015330

Trust: 0.8

db:CNVDid:CNVD-2020-27257

Trust: 0.6

db:CNNVDid:CNNVD-202004-1286

Trust: 0.6

sources: CNVD: CNVD-2020-27257 // JVNDB: JVNDB-2019-015330 // CNNVD: CNNVD-202004-1286 // NVD: CVE-2019-20702

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-20702

Trust: 2.0

url:https://kb.netgear.com/000061227/security-advisory-for-post-authentication-command-injection-on-some-routers-and-gateways-psv-2018-0394

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-20702

Trust: 0.8

sources: CNVD: CNVD-2020-27257 // JVNDB: JVNDB-2019-015330 // CNNVD: CNNVD-202004-1286 // NVD: CVE-2019-20702

CREDITS

cisk

Trust: 0.6

sources: CNNVD: CNNVD-202004-1286

SOURCES

db:CNVDid:CNVD-2020-27257
db:JVNDBid:JVNDB-2019-015330
db:CNNVDid:CNNVD-202004-1286
db:NVDid:CVE-2019-20702

LAST UPDATE DATE

2024-11-23T21:59:21.284000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-27257date:2020-05-09T00:00:00
db:JVNDBid:JVNDB-2019-015330date:2020-05-12T00:00:00
db:CNNVDid:CNNVD-202004-1286date:2020-04-26T00:00:00
db:NVDid:CVE-2019-20702date:2024-11-21T04:39:07.330

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-27257date:2020-05-09T00:00:00
db:JVNDBid:JVNDB-2019-015330date:2020-05-12T00:00:00
db:CNNVDid:CNNVD-202004-1286date:2020-04-16T00:00:00
db:NVDid:CVE-2019-20702date:2020-04-16T19:15:24.087