ID

VAR-202103-1283


CVE

CVE-2021-29080


TITLE

plural  NETGEAR  Vulnerability related to password management function in devices

Trust: 0.8

sources: JVNDB: JVNDB-2021-004585

DESCRIPTION

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126. plural NETGEAR A vulnerability exists in the device regarding the password management function.Information may be obtained and information may be tampered with. This affects RBK852 prior to 3.2.10.11, RBK853 prior to 3.2.10.11, RBR854 prior to 3.2.10.11, RBR850 prior to 3.2.10.11, RBS850 prior to 3.2.10.11, CBR40 prior to 2.5.0.10, R7000 prior to 1.0.11.116, R6900P prior to 1.3.2.126, R7900 prior to 1.0.4.38, R7960P prior to 1.4.1.66, R8000 prior to 1.0.4.66, R7900P prior to 1.4.1.66, R8000P prior to 1.4.1.66, RAX75 prior to 1.0.3.102, RAX80 prior to 1.0.3.102, and R7000P prior to 1.3.2.126

Trust: 1.71

sources: NVD: CVE-2021-29080 // JVNDB: JVNDB-2021-004585 // VULMON: CVE-2021-29080

AFFECTED PRODUCTS

vendor:netgearmodel:rbk852scope:ltversion:3.2.10.11

Trust: 1.0

vendor:netgearmodel:cbr40scope:ltversion:2.5.0.10

Trust: 1.0

vendor:netgearmodel:r8000scope:ltversion:1.0.4.66

Trust: 1.0

vendor:netgearmodel:r7960pscope:ltversion:1.4.1.66

Trust: 1.0

vendor:netgearmodel:r7000scope:ltversion:1.0.11.116

Trust: 1.0

vendor:netgearmodel:r6900pscope:ltversion:1.3.2.126

Trust: 1.0

vendor:netgearmodel:rbk853scope:ltversion:3.2.10.11

Trust: 1.0

vendor:netgearmodel:rax80scope:ltversion:1.0.3.102

Trust: 1.0

vendor:netgearmodel:r7000pscope:ltversion:1.3.2.126

Trust: 1.0

vendor:netgearmodel:rax75scope:ltversion:1.0.3.102

Trust: 1.0

vendor:netgearmodel:r7900scope:ltversion:1.0.4.38

Trust: 1.0

vendor:netgearmodel:r8000pscope:ltversion:1.4.1.66

Trust: 1.0

vendor:netgearmodel:r7900pscope:ltversion:1.4.1.66

Trust: 1.0

vendor:netgearmodel:rbs850scope:ltversion:3.2.10.11

Trust: 1.0

vendor:netgearmodel:rbr850scope:ltversion:3.2.10.11

Trust: 1.0

vendor:netgearmodel:rbr854scope:ltversion:3.2.10.11

Trust: 1.0

vendor:ネットギアmodel:rbk852scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbk853scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbr854scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbr850scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r7900scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r6900pscope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rbs850scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r7960pscope: - version: -

Trust: 0.8

vendor:ネットギアmodel:cbr40scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:r7000scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-004585 // NVD: CVE-2021-29080

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-29080
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2021-29080
value: HIGH

Trust: 1.0

NVD: CVE-2021-29080
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202103-1343
value: HIGH

Trust: 0.6

VULMON: CVE-2021-29080
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-29080
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-29080
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 5.2
version: 3.1

Trust: 2.0

OTHER: JVNDB-2021-004585
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-29080 // JVNDB: JVNDB-2021-004585 // CNNVD: CNNVD-202103-1343 // NVD: CVE-2021-29080 // NVD: CVE-2021-29080

PROBLEMTYPE DATA

problemtype:CWE-640

Trust: 1.0

problemtype:Weak password recovery mechanism when you forget your password (CWE-640) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-004585 // NVD: CVE-2021-29080

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202103-1343

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202103-1343

PATCH

title:Security Advisory for Pre-authentication Password Reset on Some Routers and WiFi Systems, PSV-2019-0150url:https://kb.netgear.com/000063007/Security-Advisory-for-Pre-authentication-Password-Reset-on-Some-Routers-and-WiFi-Systems-PSV-2019-0150

Trust: 0.8

title:Certain NETGEAR Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=145159

Trust: 0.6

sources: JVNDB: JVNDB-2021-004585 // CNNVD: CNNVD-202103-1343

EXTERNAL IDS

db:NVDid:CVE-2021-29080

Trust: 2.5

db:JVNDBid:JVNDB-2021-004585

Trust: 0.8

db:CNNVDid:CNNVD-202103-1343

Trust: 0.6

db:VULMONid:CVE-2021-29080

Trust: 0.1

sources: VULMON: CVE-2021-29080 // JVNDB: JVNDB-2021-004585 // CNNVD: CNNVD-202103-1343 // NVD: CVE-2021-29080

REFERENCES

url:https://kb.netgear.com/000063007/security-advisory-for-pre-authentication-password-reset-on-some-routers-and-wifi-systems-psv-2019-0150

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-29080

Trust: 1.4

url:https://cwe.mitre.org/data/definitions/640.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-29080 // JVNDB: JVNDB-2021-004585 // CNNVD: CNNVD-202103-1343 // NVD: CVE-2021-29080

SOURCES

db:VULMONid:CVE-2021-29080
db:JVNDBid:JVNDB-2021-004585
db:CNNVDid:CNNVD-202103-1343
db:NVDid:CVE-2021-29080

LAST UPDATE DATE

2024-11-23T22:57:57.955000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-29080date:2021-03-24T00:00:00
db:JVNDBid:JVNDB-2021-004585date:2021-11-25T03:10:00
db:CNNVDid:CNNVD-202103-1343date:2021-08-16T00:00:00
db:NVDid:CVE-2021-29080date:2024-11-21T06:00:40.337

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-29080date:2021-03-23T00:00:00
db:JVNDBid:JVNDB-2021-004585date:2021-11-25T00:00:00
db:CNNVDid:CNNVD-202103-1343date:2021-03-23T00:00:00
db:NVDid:CVE-2021-29080date:2021-03-23T07:15:14.217