ID

VAR-202012-1177


CVE

CVE-2020-35802


TITLE

plural  NETGEAR  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-014795

DESCRIPTION

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 before 2.6.1.4, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, and RBS40V before 2.6.1.4. plural NETGEAR An unspecified vulnerability exists in the device.Information may be obtained

Trust: 1.62

sources: NVD: CVE-2020-35802 // JVNDB: JVNDB-2020-014795

AFFECTED PRODUCTS

vendor:netgearmodel:cbr40scope:ltversion:2.5.0.14

Trust: 1.0

vendor:netgearmodel:rbr840scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbs850scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbs750scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbk852scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbs840scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rax80scope:ltversion:1.0.3.102

Trust: 1.0

vendor:netgearmodel:rbw30scope:ltversion:2.6.1.4

Trust: 1.0

vendor:netgearmodel:rbs840vscope:ltversion:2.6.1.4

Trust: 1.0

vendor:netgearmodel:rax75scope:ltversion:1.0.3.102

Trust: 1.0

vendor:netgearmodel:rbk842scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbr750scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbr850scope:ltversion:3.2.16.6

Trust: 1.0

vendor:netgearmodel:rbk752scope:ltversion:3.2.16.6

Trust: 1.0

vendor:ネットギアmodel:rbs750scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbr850scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rax80scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbr750scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rax75scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbs850scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbk852scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbk752scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbw30scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-014795 // NVD: CVE-2020-35802

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-35802
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2020-35802
value: HIGH

Trust: 1.0

NVD: CVE-2020-35802
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202012-1767
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-35802
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-35802
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

OTHER: JVNDB-2020-014795
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-014795 // CNNVD: CNNVD-202012-1767 // NVD: CVE-2020-35802 // NVD: CVE-2020-35802

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-014795 // NVD: CVE-2020-35802

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202012-1767

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202012-1767

PATCH

title:Security Advisory for Sensitive Information Disclosure on Some Routers and WiFi Systems, PSV-2020-0331url:https://kb.netgear.com/000062720/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-and-WiFi-Systems-PSV-2020-0331

Trust: 0.8

title:Multiple Netgear Product information disclosure vulnerability repair measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=138274

Trust: 0.6

sources: JVNDB: JVNDB-2020-014795 // CNNVD: CNNVD-202012-1767

EXTERNAL IDS

db:NVDid:CVE-2020-35802

Trust: 2.4

db:JVNDBid:JVNDB-2020-014795

Trust: 0.8

db:CNNVDid:CNNVD-202012-1767

Trust: 0.6

sources: JVNDB: JVNDB-2020-014795 // CNNVD: CNNVD-202012-1767 // NVD: CVE-2020-35802

REFERENCES

url:https://kb.netgear.com/000062720/security-advisory-for-sensitive-information-disclosure-on-some-routers-and-wifi-systems-psv-2020-0331

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-35802

Trust: 1.4

sources: JVNDB: JVNDB-2020-014795 // CNNVD: CNNVD-202012-1767 // NVD: CVE-2020-35802

SOURCES

db:JVNDBid:JVNDB-2020-014795
db:CNNVDid:CNNVD-202012-1767
db:NVDid:CVE-2020-35802

LAST UPDATE DATE

2024-11-23T22:58:05.584000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-014795date:2021-08-31T05:14:00
db:CNNVDid:CNNVD-202012-1767date:2021-01-05T00:00:00
db:NVDid:CVE-2020-35802date:2024-11-21T05:28:09.167

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-014795date:2021-08-31T00:00:00
db:CNNVDid:CNNVD-202012-1767date:2020-12-29T00:00:00
db:NVDid:CVE-2020-35802date:2020-12-30T00:15:14.517