ID

VAR-202010-0564


CVE

CVE-2020-26898


TITLE

NETGEAR RAX40  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-012275

DESCRIPTION

NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings. NETGEAR RAX40 An unspecified vulnerability exists in the device.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-26898 // JVNDB: JVNDB-2020-012275

AFFECTED PRODUCTS

vendor:netgearmodel:rax40scope:ltversion:1.0.3.80

Trust: 1.0

vendor:ネットギアmodel:rax40scope:eqversion: -

Trust: 0.8

vendor:ネットギアmodel:rax40scope:ltversion:rax40 firmware 1.0.3.80 less than

Trust: 0.8

sources: JVNDB: JVNDB-2020-012275 // NVD: CVE-2020-26898

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-26898
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2020-26898
value: CRITICAL

Trust: 1.0

NVD: CVE-2020-26898
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202010-328
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-26898
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-26898
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2020-26898
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2020-26898
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-012275 // CNNVD: CNNVD-202010-328 // NVD: CVE-2020-26898 // NVD: CVE-2020-26898

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:Other (CWE-Other) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-012275 // NVD: CVE-2020-26898

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202010-328

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202010-328

PATCH

title:Security Advisory for Security Misconfiguration on RAX40, PSV-2019-0267url:https://kb.netgear.com/000062356/Security-Advisory-for-Security-Misconfiguration-on-RAX40-PSV-2019-0267

Trust: 0.8

title:NETGEAR RAX40 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131117

Trust: 0.6

sources: JVNDB: JVNDB-2020-012275 // CNNVD: CNNVD-202010-328

EXTERNAL IDS

db:NVDid:CVE-2020-26898

Trust: 2.4

db:JVNDBid:JVNDB-2020-012275

Trust: 0.8

db:CNNVDid:CNNVD-202010-328

Trust: 0.6

sources: JVNDB: JVNDB-2020-012275 // CNNVD: CNNVD-202010-328 // NVD: CVE-2020-26898

REFERENCES

url:https://kb.netgear.com/000062356/security-advisory-for-security-misconfiguration-on-rax40-psv-2019-0267

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-26898

Trust: 1.4

sources: JVNDB: JVNDB-2020-012275 // CNNVD: CNNVD-202010-328 // NVD: CVE-2020-26898

SOURCES

db:JVNDBid:JVNDB-2020-012275
db:CNNVDid:CNNVD-202010-328
db:NVDid:CVE-2020-26898

LAST UPDATE DATE

2024-11-23T23:11:16.411000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-012275date:2021-04-28T07:36:00
db:CNNVDid:CNNVD-202010-328date:2020-10-21T00:00:00
db:NVDid:CVE-2020-26898date:2024-11-21T05:20:26.500

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-012275date:2021-04-28T00:00:00
db:CNNVDid:CNNVD-202010-328date:2020-10-09T00:00:00
db:NVDid:CVE-2020-26898date:2020-10-09T07:15:13.293