ID

VAR-202004-1577


CVE

CVE-2018-21141


TITLE

plural NETGEAR Input verification vulnerabilities on devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-016295

DESCRIPTION

Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64. plural NETGEAR The device contains an input verification vulnerability.Service operation interruption (DoS) It may be put into a state. NETGEAR R7800, etc. are all wireless routers from NETGEAR. There are security vulnerabilities in many NETGEAR products

Trust: 2.16

sources: NVD: CVE-2018-21141 // JVNDB: JVNDB-2018-016295 // CNVD: CNVD-2021-61050

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-61050

AFFECTED PRODUCTS

vendor:netgearmodel:r7500scope:ltversion:1.0.0.122

Trust: 1.6

vendor:netgearmodel:wndr4300scope:ltversion:1.0.2.98

Trust: 1.6

vendor:netgearmodel:r6100scope:ltversion:1.0.1.22

Trust: 1.6

vendor:netgearmodel:r7800scope:ltversion:1.0.2.42

Trust: 1.6

vendor:netgearmodel:r8900scope:ltversion:1.0.3.10

Trust: 1.6

vendor:netgearmodel:r9000scope:ltversion:1.0.3.10

Trust: 1.6

vendor:netgearmodel:wndr3700scope:ltversion:1.0.2.96

Trust: 1.0

vendor:netgearmodel:wnr2000scope:ltversion:1.0.0.64

Trust: 1.0

vendor:netgearmodel:wndr4500scope:ltversion:1.0.0.54

Trust: 1.0

vendor:netgearmodel:wndr4300scope:ltversion:1.0.0.54

Trust: 1.0

vendor:netgearmodel:r6100scope:eqversion:1.0.1.22

Trust: 0.8

vendor:netgearmodel:r7500scope:eqversion:1.0.0.122

Trust: 0.8

vendor:netgearmodel:r7800scope:eqversion:1.0.2.42

Trust: 0.8

vendor:netgearmodel:r8900scope:eqversion:1.0.3.10

Trust: 0.8

vendor:netgearmodel:r9000scope:eqversion:1.0.3.10

Trust: 0.8

vendor:netgearmodel:wndr3700scope:eqversion:1.0.2.96

Trust: 0.8

vendor:netgearmodel:wndr4300scope:eqversion:1.0.0.54

Trust: 0.8

vendor:netgearmodel:wndr4300scope:eqversion:1.0.2.98

Trust: 0.8

vendor:netgearmodel:wndr4500scope:eqversion:1.0.0.54

Trust: 0.8

vendor:netgearmodel:wnr2000scope:eqversion:1.0.0.64

Trust: 0.8

vendor:netgearmodel:wndr4300v2scope:ltversion:1.0.0.54

Trust: 0.6

vendor:netgearmodel:wndr4500v3scope:ltversion:1.0.0.54

Trust: 0.6

vendor:netgearmodel:wnr2000v5scope:ltversion:1.0.0.64

Trust: 0.6

vendor:netgearmodel:wndr3700v4scope:ltversion:1.0.2.96

Trust: 0.6

sources: CNVD: CNVD-2021-61050 // JVNDB: JVNDB-2018-016295 // NVD: CVE-2018-21141

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-21141
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2018-21141
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2018-016295
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2021-61050
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2018-21141
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2018-016295
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:N/I:N/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2021-61050
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-21141
baseSeverity: MEDIUM
baseScore: 4.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2018-21141
baseSeverity: MEDIUM
baseScore: 4.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.0

Trust: 1.0

NVD: JVNDB-2018-016295
baseSeverity: MEDIUM
baseScore: 4.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-61050 // JVNDB: JVNDB-2018-016295 // NVD: CVE-2018-21141 // NVD: CVE-2018-21141

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2018-016295 // NVD: CVE-2018-21141

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-1842

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-016295

PATCH

title:Security Advisory for Denial of Service on Some Routers, PSV-2017-3168url:https://kb.netgear.com/000059492/Security-Advisory-for-Denial-of-Service-on-Some-Routers-PSV-2017-3168

Trust: 0.8

title:Patch for Multiple NETGEAR products input verification error vulnerability (CNVD-2021-61050)url:https://www.cnvd.org.cn/patchInfo/show/284571

Trust: 0.6

title:Multiple NETGEAR Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116318

Trust: 0.6

sources: CNVD: CNVD-2021-61050 // JVNDB: JVNDB-2018-016295 // CNNVD: CNNVD-202004-1842

EXTERNAL IDS

db:NVDid:CVE-2018-21141

Trust: 3.0

db:JVNDBid:JVNDB-2018-016295

Trust: 0.8

db:CNVDid:CNVD-2021-61050

Trust: 0.6

db:CNNVDid:CNNVD-202004-1842

Trust: 0.6

sources: CNVD: CNVD-2021-61050 // JVNDB: JVNDB-2018-016295 // CNNVD: CNNVD-202004-1842 // NVD: CVE-2018-21141

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2018-21141

Trust: 2.0

url:https://kb.netgear.com/000059492/security-advisory-for-denial-of-service-on-some-routers-psv-2017-3168

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-21141

Trust: 0.8

sources: CNVD: CNVD-2021-61050 // JVNDB: JVNDB-2018-016295 // CNNVD: CNNVD-202004-1842 // NVD: CVE-2018-21141

SOURCES

db:CNVDid:CNVD-2021-61050
db:JVNDBid:JVNDB-2018-016295
db:CNNVDid:CNNVD-202004-1842
db:NVDid:CVE-2018-21141

LAST UPDATE DATE

2024-11-23T22:48:01.361000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-61050date:2021-08-11T00:00:00
db:JVNDBid:JVNDB-2018-016295date:2020-05-21T00:00:00
db:CNNVDid:CNNVD-202004-1842date:2020-04-22T00:00:00
db:NVDid:CVE-2018-21141date:2024-11-21T04:03:00.047

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-61050date:2021-08-08T00:00:00
db:JVNDBid:JVNDB-2018-016295date:2020-05-21T00:00:00
db:CNNVDid:CNNVD-202004-1842date:2020-04-21T00:00:00
db:NVDid:CVE-2018-21141date:2020-04-21T21:15:12.740