ID

VAR-202004-0791


CVE

CVE-2019-20745


TITLE

NETGEAR WAC505 and WAC510 On the device OS Command injection vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2019-015323

DESCRIPTION

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2. NETGEAR WAC505 and WAC510 On the device OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2019-20745 // JVNDB: JVNDB-2019-015323

AFFECTED PRODUCTS

vendor:netgearmodel:wac505scope:ltversion:5.0.10.2

Trust: 1.0

vendor:netgearmodel:wac510scope:ltversion:5.0.10.2

Trust: 1.0

vendor:netgearmodel:wac505scope:eqversion:5.0.10.2

Trust: 0.8

vendor:netgearmodel:wac510scope:eqversion:5.0.10.2

Trust: 0.8

sources: JVNDB: JVNDB-2019-015323 // NVD: CVE-2019-20745

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-20745
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2019-20745
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2019-015323
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202004-1356
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2019-20745
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2019-015323
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2019-20745
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2019-20745
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 0.9
impactScore: 5.5
version: 3.0

Trust: 1.0

NVD: JVNDB-2019-015323
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2019-015323 // CNNVD: CNNVD-202004-1356 // NVD: CVE-2019-20745 // NVD: CVE-2019-20745

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:CWE-78

Trust: 0.8

sources: JVNDB: JVNDB-2019-015323 // NVD: CVE-2019-20745

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202004-1356

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-202004-1356

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-015323

PATCH

title:Security Advisory for Post-Authentication Command Injection on WAC505 and WAC510, PSV-2018-0610url:https://kb.netgear.com/000060978/Security-Advisory-for-Post-Authentication-Command-Injection-on-WAC505-and-WAC510-PSV-2018-0610

Trust: 0.8

title:NETGEAR WAC505 and WAC510 Fixes for operating system command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116895

Trust: 0.6

sources: JVNDB: JVNDB-2019-015323 // CNNVD: CNNVD-202004-1356

EXTERNAL IDS

db:NVDid:CVE-2019-20745

Trust: 2.4

db:JVNDBid:JVNDB-2019-015323

Trust: 0.8

db:CNNVDid:CNNVD-202004-1356

Trust: 0.6

sources: JVNDB: JVNDB-2019-015323 // CNNVD: CNNVD-202004-1356 // NVD: CVE-2019-20745

REFERENCES

url:https://kb.netgear.com/000060978/security-advisory-for-post-authentication-command-injection-on-wac505-and-wac510-psv-2018-0610

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-20745

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-20745

Trust: 0.8

sources: JVNDB: JVNDB-2019-015323 // CNNVD: CNNVD-202004-1356 // NVD: CVE-2019-20745

SOURCES

db:JVNDBid:JVNDB-2019-015323
db:CNNVDid:CNNVD-202004-1356
db:NVDid:CVE-2019-20745

LAST UPDATE DATE

2024-11-23T22:05:44.182000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2019-015323date:2020-05-12T00:00:00
db:CNNVDid:CNNVD-202004-1356date:2020-04-26T00:00:00
db:NVDid:CVE-2019-20745date:2024-11-21T04:39:14.967

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2019-015323date:2020-05-12T00:00:00
db:CNNVDid:CNNVD-202004-1356date:2020-04-16T00:00:00
db:NVDid:CVE-2019-20745date:2020-04-16T21:15:12.707