ID

VAR-202012-1179


CVE

CVE-2020-35804


TITLE

plural  NETGEAR  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-014796

DESCRIPTION

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34. plural NETGEAR An unspecified vulnerability exists in the device.Information may be obtained

Trust: 1.62

sources: NVD: CVE-2020-35804 // JVNDB: JVNDB-2020-014796

AFFECTED PRODUCTS

vendor:netgearmodel:d7800scope:ltversion:1.0.1.58

Trust: 1.0

vendor:netgearmodel:r7800scope:ltversion:1.0.2.74

Trust: 1.0

vendor:netgearmodel:r8900scope:ltversion:1.0.5.18

Trust: 1.0

vendor:netgearmodel:r9000scope:ltversion:1.0.5.18

Trust: 1.0

vendor:netgearmodel:xr700scope:ltversion:1.0.1.34

Trust: 1.0

vendor:ネットギアmodel:xr700scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:d7800scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r9000scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r7800scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r8900scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-014796 // NVD: CVE-2020-35804

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-35804
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2020-35804
value: HIGH

Trust: 1.0

NVD: CVE-2020-35804
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202012-1739
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-35804
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-35804
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2020-35804
baseSeverity: HIGH
baseScore: 7.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2020-35804
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-014796 // CNNVD: CNNVD-202012-1739 // NVD: CVE-2020-35804 // NVD: CVE-2020-35804

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-014796 // NVD: CVE-2020-35804

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202012-1739

PATCH

title:Security Advisory for Sensitive Information Disclosure on Some Routers, PSV-2019-0254url:https://kb.netgear.com/000062716/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-PSV-2019-0254

Trust: 0.8

sources: JVNDB: JVNDB-2020-014796

EXTERNAL IDS

db:NVDid:CVE-2020-35804

Trust: 2.4

db:JVNDBid:JVNDB-2020-014796

Trust: 0.8

db:CNNVDid:CNNVD-202012-1739

Trust: 0.6

sources: JVNDB: JVNDB-2020-014796 // CNNVD: CNNVD-202012-1739 // NVD: CVE-2020-35804

REFERENCES

url:https://kb.netgear.com/000062716/security-advisory-for-sensitive-information-disclosure-on-some-routers-psv-2019-0254

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-35804

Trust: 1.4

sources: JVNDB: JVNDB-2020-014796 // CNNVD: CNNVD-202012-1739 // NVD: CVE-2020-35804

SOURCES

db:JVNDBid:JVNDB-2020-014796
db:CNNVDid:CNNVD-202012-1739
db:NVDid:CVE-2020-35804

LAST UPDATE DATE

2024-11-23T21:51:07.004000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-014796date:2021-08-31T05:14:00
db:CNNVDid:CNNVD-202012-1739date:2021-01-05T00:00:00
db:NVDid:CVE-2020-35804date:2024-11-21T05:28:09.547

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-014796date:2021-08-31T00:00:00
db:CNNVDid:CNNVD-202012-1739date:2020-12-29T00:00:00
db:NVDid:CVE-2020-35804date:2020-12-30T00:15:14.627