ID

VAR-202004-1466


CVE

CVE-2017-18706


TITLE

plural NETGEAR Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2017-015004

DESCRIPTION

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6100 before 1.0.1.20, R7500 before 1.0.0.118, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.62. plural NETGEAR An unspecified vulnerability exists in the device.Service operation interruption (DoS) It may be put into a state. NETGEAR R7500 is a wireless router of NETGEAR. There are security holes in many NETGEAR products. No detailed vulnerability details are currently available. This affects R6100 prior to 1.0.1.20, R7500 prior to 1.0.0.118, WNDR3700v4 prior to 1.0.2.88, WNDR4300 prior to 1.0.2.90, WNDR4300v2 prior to 1.0.0.48, WNDR4500v3 prior to 1.0.0.48, and WNR2000v5 prior to 1.0.0.62

Trust: 2.25

sources: NVD: CVE-2017-18706 // JVNDB: JVNDB-2017-015004 // CNVD: CNVD-2020-28006 // VULMON: CVE-2017-18706

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-28006

AFFECTED PRODUCTS

vendor:netgearmodel:r6100scope:ltversion:1.0.1.20

Trust: 1.6

vendor:netgearmodel:r7500scope:ltversion:1.0.0.118

Trust: 1.6

vendor:netgearmodel:wndr4300scope:ltversion:1.0.2.90

Trust: 1.6

vendor:netgearmodel:wndr4500scope:ltversion:1.0.0.48

Trust: 1.0

vendor:netgearmodel:wndr4300scope:ltversion:1.0.0.48

Trust: 1.0

vendor:netgearmodel:wnr2000scope:ltversion:1.0.0.62

Trust: 1.0

vendor:netgearmodel:wndr3700scope:ltversion:1.0.2.88

Trust: 1.0

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.48

Trust: 0.9

vendor:netgearmodel:r6100scope:eqversion:1.0.1.20

Trust: 0.8

vendor:netgearmodel:r7500scope:eqversion:1.0.0.118

Trust: 0.8

vendor:netgearmodel:wndr3700scope:eqversion:1.0.2.88

Trust: 0.8

vendor:netgearmodel:wndr4300scope:eqversion:1.0.2.90

Trust: 0.8

vendor:netgearmodel:wndr4500scope:eqversion:1.0.0.48

Trust: 0.8

vendor:netgearmodel:wnr2000scope:eqversion:1.0.0.62

Trust: 0.8

vendor:netgearmodel:wndr4500v3scope:ltversion:1.0.0.48

Trust: 0.6

vendor:netgearmodel:wndr4300v2scope:ltversion:1.0.0.48

Trust: 0.6

vendor:netgearmodel:wndr3700v4scope:ltversion:1.0.2.88

Trust: 0.6

vendor:netgearmodel:wnr2000v5scope:ltversion:1.0.0.62

Trust: 0.6

vendor:netgearmodel:r6100scope:eqversion:1.0.1.12

Trust: 0.1

vendor:netgearmodel:r6100scope:eqversion:1.0.1.14

Trust: 0.1

vendor:netgearmodel:r6100scope:eqversion:1.0.1.16

Trust: 0.1

vendor:netgearmodel:r7500scope:eqversion:1.0.0.108

Trust: 0.1

vendor:netgearmodel:r7500scope:eqversion:1.0.0.110

Trust: 0.1

vendor:netgearmodel:r7500scope:eqversion:1.0.0.112

Trust: 0.1

vendor:netgearmodel:r7500scope:eqversion:1.0.0.116

Trust: 0.1

vendor:netgearmodel:wndr3700scope:eqversion: -

Trust: 0.1

vendor:netgearmodel:wndr3700scope:eqversion:1.0.2.86

Trust: 0.1

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.50

Trust: 0.1

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.52

Trust: 0.1

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.54

Trust: 0.1

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.56

Trust: 0.1

vendor:netgearmodel:wndr4300scope:eqversion:1.0.2.88

Trust: 0.1

vendor:netgearmodel:wndr4500scope:eqversion: -

Trust: 0.1

vendor:netgearmodel:wnr2000scope:eqversion:1.0.0.42

Trust: 0.1

vendor:netgearmodel:wnr2000scope:eqversion:1.0.0.48

Trust: 0.1

vendor:netgearmodel:wnr2000scope:eqversion:1.0.0.58

Trust: 0.1

sources: CNVD: CNVD-2020-28006 // VULMON: CVE-2017-18706 // JVNDB: JVNDB-2017-015004 // NVD: CVE-2017-18706

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-18706
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2017-18706
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2017-015004
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-28006
value: LOW

Trust: 0.6

CNNVD: CNNVD-202004-2095
value: MEDIUM

Trust: 0.6

VULMON: CVE-2017-18706
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-18706
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2017-015004
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-28006
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2017-18706
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2017-18706
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.0

NVD: JVNDB-2017-015004
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-28006 // VULMON: CVE-2017-18706 // JVNDB: JVNDB-2017-015004 // CNNVD: CNNVD-202004-2095 // NVD: CVE-2017-18706 // NVD: CVE-2017-18706

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2017-18706

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202004-2095

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-2095

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-015004

PATCH

title:Security Advisory for Security Misconfiguration on Some Routers, PSV-2017-0516url:https://kb.netgear.com/000053196/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-PSV-2017-0516

Trust: 0.8

title:Patch for Many NETGEAR products have unknown vulnerabilities (CNVD-2020-28006)url:https://www.cnvd.org.cn/patchInfo/show/217309

Trust: 0.6

title:Multiple NETGEAR Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=117018

Trust: 0.6

sources: CNVD: CNVD-2020-28006 // JVNDB: JVNDB-2017-015004 // CNNVD: CNNVD-202004-2095

EXTERNAL IDS

db:NVDid:CVE-2017-18706

Trust: 3.1

db:JVNDBid:JVNDB-2017-015004

Trust: 0.8

db:CNVDid:CNVD-2020-28006

Trust: 0.6

db:CNNVDid:CNNVD-202004-2095

Trust: 0.6

db:VULMONid:CVE-2017-18706

Trust: 0.1

sources: CNVD: CNVD-2020-28006 // VULMON: CVE-2017-18706 // JVNDB: JVNDB-2017-015004 // CNNVD: CNNVD-202004-2095 // NVD: CVE-2017-18706

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2017-18706

Trust: 2.0

url:https://kb.netgear.com/000053196/security-advisory-for-security-misconfiguration-on-some-routers-psv-2017-0516

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-18706

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2020-28006 // VULMON: CVE-2017-18706 // JVNDB: JVNDB-2017-015004 // CNNVD: CNNVD-202004-2095 // NVD: CVE-2017-18706

SOURCES

db:CNVDid:CNVD-2020-28006
db:VULMONid:CVE-2017-18706
db:JVNDBid:JVNDB-2017-015004
db:CNNVDid:CNNVD-202004-2095
db:NVDid:CVE-2017-18706

LAST UPDATE DATE

2024-11-23T22:25:32.514000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-28006date:2020-05-13T00:00:00
db:VULMONid:CVE-2017-18706date:2020-05-04T00:00:00
db:JVNDBid:JVNDB-2017-015004date:2020-06-03T00:00:00
db:CNNVDid:CNNVD-202004-2095date:2020-05-06T00:00:00
db:NVDid:CVE-2017-18706date:2024-11-21T03:20:42.817

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-28006date:2020-05-13T00:00:00
db:VULMONid:CVE-2017-18706date:2020-04-24T00:00:00
db:JVNDBid:JVNDB-2017-015004date:2020-06-03T00:00:00
db:CNNVDid:CNNVD-202004-2095date:2020-04-24T00:00:00
db:NVDid:CVE-2017-18706date:2020-04-24T14:15:12.483