ID

VAR-202006-0587


CVE

CVE-2020-14429


TITLE

plural NETGEAR Inadequate protection of credentials on devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-006746

DESCRIPTION

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects MK62 before 1.0.4.92, MK63 before 1.0.4.92, MR60 before 1.0.4.92, MS60 before 1.0.4.92, RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBS750 before 3.2.15.25, RBR750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25. plural NETGEAR Devices contain vulnerabilities in insufficient protection of credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. This affects MK62 prior to 1.0.4.92, MK63 prior to 1.0.4.92, MR60 prior to 1.0.4.92, MS60 prior to 1.0.4.92, RBK752 prior to 3.2.15.25, RBK753 prior to 3.2.15.25, RBK753S prior to 3.2.15.25, RBS750 prior to 3.2.15.25, RBR750 prior to 3.2.15.25, RBK842 prior to 3.2.15.25, RBR840 prior to 3.2.15.25, RBS840 prior to 3.2.15.25, RBK852 prior to 3.2.15.25, RBK853 prior to 3.2.15.25, RBR850 prior to 3.2.15.25, and RBS850 prior to 3.2.15.25

Trust: 1.71

sources: NVD: CVE-2020-14429 // JVNDB: JVNDB-2020-006746 // VULMON: CVE-2020-14429

AFFECTED PRODUCTS

vendor:netgearmodel:mk63scope:ltversion:1.0.4.92

Trust: 1.0

vendor:netgearmodel:rbr750scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbr850scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbk752scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbs850scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbs750scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbk852scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbr840scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbs840scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbk753scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:rbk853scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:ms60scope:ltversion:1.0.4.92

Trust: 1.0

vendor:netgearmodel:rbk753sscope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:mr60scope:ltversion:1.0.4.92

Trust: 1.0

vendor:netgearmodel:mk62scope:ltversion:1.0.4.92

Trust: 1.0

vendor:netgearmodel:rbk842scope:ltversion:3.2.15.25

Trust: 1.0

vendor:netgearmodel:mk62scope:eqversion:1.0.4.92

Trust: 0.8

vendor:netgearmodel:mk63scope:eqversion:1.0.4.92

Trust: 0.8

vendor:netgearmodel:mr60scope:eqversion:1.0.4.92

Trust: 0.8

vendor:netgearmodel:ms60scope:eqversion:1.0.4.92

Trust: 0.8

vendor:netgearmodel:rbk752scope:eqversion:3.2.15.25

Trust: 0.8

vendor:netgearmodel:rbk753scope:eqversion:3.2.15.25

Trust: 0.8

vendor:netgearmodel:rbk753sscope:eqversion:3.2.15.25

Trust: 0.8

vendor:netgearmodel:rbk842scope:eqversion:3.2.15.25

Trust: 0.8

vendor:netgearmodel:rbr750scope:eqversion:3.2.15.25

Trust: 0.8

vendor:netgearmodel:rbs750scope:eqversion:3.2.15.25

Trust: 0.8

sources: JVNDB: JVNDB-2020-006746 // NVD: CVE-2020-14429

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-14429
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2020-14429
value: CRITICAL

Trust: 1.0

NVD: JVNDB-2020-006746
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202006-1243
value: HIGH

Trust: 0.6

VULMON: CVE-2020-14429
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-14429
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-006746
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-14429
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2020-14429
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 6.0
version: 3.0

Trust: 1.0

NVD: JVNDB-2020-006746
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2020-14429 // JVNDB: JVNDB-2020-006746 // CNNVD: CNNVD-202006-1243 // NVD: CVE-2020-14429 // NVD: CVE-2020-14429

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-522

Trust: 0.8

sources: JVNDB: JVNDB-2020-006746 // NVD: CVE-2020-14429

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202006-1243

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202006-1243

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006746

PATCH

title:Security Advisory for Admin Credential Disclosure on Some WiFi Systems, PSV-2020-0050url:https://kb.netgear.com/000061938/Security-Advisory-for-Admin-Credential-Disclosure-on-Some-WiFi-Systems-PSV-2020-0050

Trust: 0.8

title:Multiple NETGEAR Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=121991

Trust: 0.6

sources: JVNDB: JVNDB-2020-006746 // CNNVD: CNNVD-202006-1243

EXTERNAL IDS

db:NVDid:CVE-2020-14429

Trust: 2.5

db:JVNDBid:JVNDB-2020-006746

Trust: 0.8

db:CNNVDid:CNNVD-202006-1243

Trust: 0.6

db:VULMONid:CVE-2020-14429

Trust: 0.1

sources: VULMON: CVE-2020-14429 // JVNDB: JVNDB-2020-006746 // CNNVD: CNNVD-202006-1243 // NVD: CVE-2020-14429

REFERENCES

url:https://kb.netgear.com/000061938/security-advisory-for-admin-credential-disclosure-on-some-wifi-systems-psv-2020-0050

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-14429

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-14429

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2020-14429 // JVNDB: JVNDB-2020-006746 // CNNVD: CNNVD-202006-1243 // NVD: CVE-2020-14429

SOURCES

db:VULMONid:CVE-2020-14429
db:JVNDBid:JVNDB-2020-006746
db:CNNVDid:CNNVD-202006-1243
db:NVDid:CVE-2020-14429

LAST UPDATE DATE

2024-11-23T22:33:26.219000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-14429date:2021-07-21T00:00:00
db:JVNDBid:JVNDB-2020-006746date:2020-07-16T00:00:00
db:CNNVDid:CNNVD-202006-1243date:2020-06-22T00:00:00
db:NVDid:CVE-2020-14429date:2024-11-21T05:03:14.980

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-14429date:2020-06-18T00:00:00
db:JVNDBid:JVNDB-2020-006746date:2020-07-16T00:00:00
db:CNNVDid:CNNVD-202006-1243date:2020-06-18T00:00:00
db:NVDid:CVE-2020-14429date:2020-06-18T17:15:12.077