ID

VAR-202108-1620


CVE

CVE-2021-38514


TITLE

Multiple Netgear Product Authorization Issue Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202108-962

DESCRIPTION

Certain NETGEAR devices are affected by authentication bypass. This affects D3600 prior to 1.0.0.72, D6000 prior to 1.0.0.72, D6100 prior to 1.0.0.63, D6200 prior to 1.1.00.34, D6220 prior to 1.0.0.48, D6400 prior to 1.0.0.86, D7000 prior to 1.0.1.70, D7000v2 prior to 1.0.0.52, D7800 prior to 1.0.1.56, D8500 prior to 1.0.3.44, DC112A prior to 1.0.0.42, DGN2200v4 prior to 1.0.0.108, DGND2200Bv4 prior to 1.0.0.108, EX2700 prior to 1.0.1.48, EX3700 prior to 1.0.0.76, EX3800 prior to 1.0.0.76, EX6000 prior to 1.0.0.38, EX6100 prior to 1.0.2.24, EX6100v2 prior to 1.0.1.76, EX6120 prior to 1.0.0.42, EX6130 prior to 1.0.0.28, EX6150v1 prior to 1.0.0.42, EX6150v2 prior to 1.0.1.76, EX6200 prior to 1.0.3.88, EX6200v2 prior to 1.0.1.72, EX6400 prior to 1.0.2.136, EX7000 prior to 1.0.0.66, EX7300 prior to 1.0.2.136, EX8000 prior to 1.0.1.180, RBK50 prior to 2.1.4.10, RBR50 prior to 2.1.4.10, RBS50 prior to 2.1.4.10, RBK40 prior to 2.1.4.10, RBR40 prior to 2.1.4.10, RBS40 prior to 2.1.4.10, RBW30 prior to 2.2.1.204, PR2000 prior to 1.0.0.28, R6020 prior to 1.0.0.38, R6080 prior to 1.0.0.38, R6050 prior to 1.0.1.18, JR6150 prior to 1.0.1.18, R6120 prior to 1.0.0.46, R6220 prior to 1.1.0.86, R6250 prior to 1.0.4.34, R6300v2 prior to 1.0.4.32, R6400 prior to 1.0.1.44, R6400v2 prior to 1.0.2.62, R6700 prior to 1.0.1.48, R6700v2 prior to 1.2.0.36, R6800 prior to 1.2.0.36, R6900v2 prior to 1.2.0.36, R6900 prior to 1.0.1.48, R7000 prior to 1.0.9.34, R6900P prior to 1.3.1.64, R7000P prior to 1.3.1.64, R7100LG prior to 1.0.0.48, R7300DST prior to 1.0.0.70, R7500v2 prior to 1.0.3.38, R7800 prior to 1.0.2.52, R7900 prior to 1.0.3.8, R8000 prior to 1.0.4.28, R7900P prior to 1.4.1.30, R8000P prior to 1.4.1.30, R8300 prior to 1.0.2.128, R8500 prior to 1.0.2.128, R9000 prior to 1.0.3.10, RBS40V prior to 2.2.0.58, RBK50V prior to 2.2.0.58, WN2000RPTv3 prior to 1.0.1.32, WN2500RPv2 prior to 1.0.1.54, WN3000RPv3 prior to 1.0.2.78, WN3100RPv2 prior to 1.0.0.66, WNDR3400v3 prior to 1.0.1.22, WNDR3700v4 prior to 1.0.2.102, WNDR4300v1 prior to 1.0.2.104, WNDR4300v2 prior to 1.0.0.56, WNDR4500v3 prior to 1.0.0.56, WNR2000v5 (R2000) prior to 1.0.0.66, WNR2020 prior to 1.1.0.62, WNR2050 prior to 1.1.0.62, WNR3500Lv2 prior to 1.2.0.62, and XR500 prior to 2.3.2.22.

Trust: 0.1

sources: VULMON: CVE-2021-38514

AFFECTED PRODUCTS

vendor:netgearmodel:r6400scope:ltversion:1.0.2.62

Trust: 1.0

vendor:netgearmodel:wnr2020scope:ltversion:1.1.0.62

Trust: 1.0

vendor:netgearmodel:wndr4300scope:ltversion:1.0.2.104

Trust: 1.0

vendor:netgearmodel:rbw30scope:ltversion:2.2.1.204

Trust: 1.0

vendor:netgearmodel:d6220scope:ltversion:1.0.0.48

Trust: 1.0

vendor:netgearmodel:wn2500rpscope:ltversion:1.0.1.54

Trust: 1.0

vendor:netgearmodel:wnr2000scope:ltversion:1.0.0.66

Trust: 1.0

vendor:netgearmodel:d7800scope:ltversion:1.0.1.56

Trust: 1.0

vendor:netgearmodel:ex6000scope:ltversion:1.0.0.38

Trust: 1.0

vendor:netgearmodel:r6120scope:ltversion:1.0.0.46

Trust: 1.0

vendor:netgearmodel:r6400scope:ltversion:1.0.1.44

Trust: 1.0

vendor:netgearmodel:ex2700scope:ltversion:1.0.1.48

Trust: 1.0

vendor:netgearmodel:r6800scope:ltversion:1.2.0.36

Trust: 1.0

vendor:netgearmodel:d7000scope:ltversion:1.0.0.52

Trust: 1.0

vendor:netgearmodel:wndr4500scope:ltversion:1.0.0.56

Trust: 1.0

vendor:netgearmodel:ex6200scope:ltversion:1.0.1.72

Trust: 1.0

vendor:netgearmodel:pr2000scope:ltversion:1.0.0.28

Trust: 1.0

vendor:netgearmodel:rbk40scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:r6020scope:ltversion:1.0.0.38

Trust: 1.0

vendor:netgearmodel:wndr3700scope:ltversion:1.0.2.102

Trust: 1.0

vendor:netgearmodel:d3600scope:ltversion:1.0.0.72

Trust: 1.0

vendor:netgearmodel:ex6120scope:ltversion:1.0.0.42

Trust: 1.0

vendor:netgearmodel:wndr4300scope:ltversion:1.0.0.56

Trust: 1.0

vendor:netgearmodel:ex6130scope:ltversion:1.0.0.28

Trust: 1.0

vendor:netgearmodel:r7500scope:ltversion:1.0.3.38

Trust: 1.0

vendor:netgearmodel:ex8000scope:ltversion:1.0.1.180

Trust: 1.0

vendor:netgearmodel:r8000scope:ltversion:1.0.4.28

Trust: 1.0

vendor:netgearmodel:r6080scope:ltversion:1.0.0.38

Trust: 1.0

vendor:netgearmodel:d7000scope:ltversion:1.0.1.70

Trust: 1.0

vendor:netgearmodel:d6400scope:ltversion:1.0.0.86

Trust: 1.0

vendor:netgearmodel:r6220scope:ltversion:1.1.0.86

Trust: 1.0

vendor:netgearmodel:r6900pscope:ltversion:1.3.1.64

Trust: 1.0

vendor:netgearmodel:wnr3500lscope:ltversion:1.2.0.62

Trust: 1.0

vendor:netgearmodel:r8000pscope:ltversion:1.4.1.30

Trust: 1.0

vendor:netgearmodel:r7300dstscope:ltversion:1.0.0.70

Trust: 1.0

vendor:netgearmodel:d6100scope:ltversion:1.0.0.63

Trust: 1.0

vendor:netgearmodel:r6900scope:ltversion:1.0.1.48

Trust: 1.0

vendor:netgearmodel:d6200scope:ltversion:1.1.00.34

Trust: 1.0

vendor:netgearmodel:r6300scope:ltversion:1.0.4.32

Trust: 1.0

vendor:netgearmodel:r9000scope:ltversion:1.0.3.10

Trust: 1.0

vendor:netgearmodel:r8300scope:ltversion:1.0.2.128

Trust: 1.0

vendor:netgearmodel:ex6200scope:ltversion:1.0.3.88

Trust: 1.0

vendor:netgearmodel:r8500scope:ltversion:1.0.2.128

Trust: 1.0

vendor:netgearmodel:rbs40vscope:ltversion:2.2.0.58

Trust: 1.0

vendor:netgearmodel:rbs40scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:wn3100rpscope:ltversion:1.0.0.66

Trust: 1.0

vendor:netgearmodel:jr6150scope:ltversion:1.0.1.18

Trust: 1.0

vendor:netgearmodel:r6900scope:ltversion:1.2.0.36

Trust: 1.0

vendor:netgearmodel:rbk50vscope:ltversion:2.2.0.58

Trust: 1.0

vendor:netgearmodel:xr500scope:ltversion:2.3.2.22

Trust: 1.0

vendor:netgearmodel:ex3800scope:ltversion:1.0.0.76

Trust: 1.0

vendor:netgearmodel:rbr50scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:dgnd2200bscope:ltversion:1.0.0.108

Trust: 1.0

vendor:netgearmodel:rbr40scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:ex6100scope:ltversion:1.0.1.76

Trust: 1.0

vendor:netgearmodel:r7000pscope:ltversion:1.3.1.64

Trust: 1.0

vendor:netgearmodel:r7900scope:ltversion:1.0.3.8

Trust: 1.0

vendor:netgearmodel:r7000scope:ltversion:1.0.9.34

Trust: 1.0

vendor:netgearmodel:wnr2050scope:ltversion:1.1.0.62

Trust: 1.0

vendor:netgearmodel:ex6150scope:ltversion:1.0.1.76

Trust: 1.0

vendor:netgearmodel:rbs50scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:ex3700scope:ltversion:1.0.0.76

Trust: 1.0

vendor:netgearmodel:r6700scope:ltversion:1.0.1.48

Trust: 1.0

vendor:netgearmodel:r6250scope:ltversion:1.0.4.34

Trust: 1.0

vendor:netgearmodel:dgn2200scope:ltversion:1.0.0.108

Trust: 1.0

vendor:netgearmodel:ex7000scope:ltversion:1.0.0.66

Trust: 1.0

vendor:netgearmodel:dc112ascope:ltversion:1.0.0.42

Trust: 1.0

vendor:netgearmodel:r6700scope:ltversion:1.2.0.36

Trust: 1.0

vendor:netgearmodel:ex6150scope:ltversion:1.0.0.42

Trust: 1.0

vendor:netgearmodel:rbk50scope:ltversion:2.1.4.10

Trust: 1.0

vendor:netgearmodel:r6050scope:ltversion:1.0.1.18

Trust: 1.0

vendor:netgearmodel:r7100lgscope:ltversion:1.0.0.48

Trust: 1.0

vendor:netgearmodel:r7800scope:ltversion:1.0.2.52

Trust: 1.0

vendor:netgearmodel:r7900pscope:ltversion:1.4.1.30

Trust: 1.0

vendor:netgearmodel:ex6400scope:ltversion:1.0.2.136

Trust: 1.0

vendor:netgearmodel:d8500scope:ltversion:1.0.3.44

Trust: 1.0

vendor:netgearmodel:wndr3400scope:ltversion:1.0.1.22

Trust: 1.0

vendor:netgearmodel:d6000scope:ltversion:1.0.0.72

Trust: 1.0

vendor:netgearmodel:ex6100scope:ltversion:1.0.2.24

Trust: 1.0

vendor:netgearmodel:ex7300scope:ltversion:1.0.2.136

Trust: 1.0

vendor:netgearmodel:wn2000rptscope:ltversion:1.0.1.32

Trust: 1.0

vendor:netgearmodel:wn3000rpscope:ltversion:1.0.2.78

Trust: 1.0

sources: NVD: CVE-2021-38514

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-38514
value: LOW

Trust: 1.0

cve@mitre.org: CVE-2021-38514
value: LOW

Trust: 1.0

CNNVD: CNNVD-202108-962
value: LOW

Trust: 0.6

VULMON: CVE-2021-38514
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-38514
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

nvd@nist.gov: CVE-2021-38514
baseSeverity: LOW
baseScore: 2.7
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.2
impactScore: 1.4
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-38514
baseSeverity: LOW
baseScore: 2.4
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: VULMON: CVE-2021-38514 // CNNVD: CNNVD-202108-962 // NVD: CVE-2021-38514 // NVD: CVE-2021-38514

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2021-38514

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-962

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202108-962

PATCH

title:Multiple Netgear Product access control error vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159356

Trust: 0.6

title:CVE-2021-38514url:https://github.com/AlAIAL90/CVE-2021-38514

Trust: 0.1

sources: VULMON: CVE-2021-38514 // CNNVD: CNNVD-202108-962

EXTERNAL IDS

db:NVDid:CVE-2021-38514

Trust: 1.7

db:CNNVDid:CNNVD-202108-962

Trust: 0.6

db:VULMONid:CVE-2021-38514

Trust: 0.1

sources: VULMON: CVE-2021-38514 // CNNVD: CNNVD-202108-962 // NVD: CVE-2021-38514

REFERENCES

url:https://kb.netgear.com/000063757/security-advisory-for-authentication-bypass-on-some-routers-extenders-and-wifi-systems-psv-2017-2449

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-38514

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://github.com/alaial90/cve-2021-38514

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-38514 // CNNVD: CNNVD-202108-962 // NVD: CVE-2021-38514

SOURCES

db:VULMONid:CVE-2021-38514
db:CNNVDid:CNNVD-202108-962
db:NVDid:CVE-2021-38514

LAST UPDATE DATE

2024-08-14T15:17:07.828000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-38514date:2021-08-19T00:00:00
db:CNNVDid:CNNVD-202108-962date:2022-07-14T00:00:00
db:NVDid:CVE-2021-38514date:2022-07-12T17:42:04.277

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-38514date:2021-08-11T00:00:00
db:CNNVDid:CNNVD-202108-962date:2021-08-10T00:00:00
db:NVDid:CVE-2021-38514date:2021-08-11T00:15:15.663