ID

VAR-202108-1623


CVE

CVE-2021-38517


TITLE

Netgear NETGEAR Buffer error vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202108-959

DESCRIPTION

Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, and XR300 before 1.0.3.50. This affects R6400 prior to 1.0.1.70, RAX75 prior to 1.0.4.120, RAX80 prior to 1.0.4.120, and XR300 prior to 1.0.3.50

Trust: 0.99

sources: NVD: CVE-2021-38517 // VULMON: CVE-2021-38517

AFFECTED PRODUCTS

vendor:netgearmodel:xr300scope:ltversion:1.0.3.50

Trust: 1.0

vendor:netgearmodel:r6400scope:ltversion:1.0.1.70

Trust: 1.0

vendor:netgearmodel:rax80scope:ltversion:1.0.4.120

Trust: 1.0

vendor:netgearmodel:rax75scope:ltversion:1.0.4.120

Trust: 1.0

sources: NVD: CVE-2021-38517

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-38517
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2021-38517
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202108-959
value: HIGH

Trust: 0.6

VULMON: CVE-2021-38517
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-38517
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

nvd@nist.gov: CVE-2021-38517
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-38517
baseSeverity: MEDIUM
baseScore: 6.9
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 1.7
impactScore: 4.7
version: 3.1

Trust: 1.0

sources: VULMON: CVE-2021-38517 // CNNVD: CNNVD-202108-959 // NVD: CVE-2021-38517 // NVD: CVE-2021-38517

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2021-38517

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-959

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202108-959

PATCH

title:Netgear NETGEAR Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159353

Trust: 0.6

sources: CNNVD: CNNVD-202108-959

EXTERNAL IDS

db:NVDid:CVE-2021-38517

Trust: 1.7

db:CNNVDid:CNNVD-202108-959

Trust: 0.6

db:VULMONid:CVE-2021-38517

Trust: 0.1

sources: VULMON: CVE-2021-38517 // CNNVD: CNNVD-202108-959 // NVD: CVE-2021-38517

REFERENCES

url:https://kb.netgear.com/000063772/security-advisory-for-out-of-bounds-read-and-write-on-some-routers-psv-2019-0187

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-38517

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/125.html

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/787.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-38517 // CNNVD: CNNVD-202108-959 // NVD: CVE-2021-38517

SOURCES

db:VULMONid:CVE-2021-38517
db:CNNVDid:CNNVD-202108-959
db:NVDid:CVE-2021-38517

LAST UPDATE DATE

2024-08-14T15:42:46.285000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-38517date:2021-08-19T00:00:00
db:CNNVDid:CNNVD-202108-959date:2021-08-20T00:00:00
db:NVDid:CVE-2021-38517date:2021-08-19T11:16:47.543

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-38517date:2021-08-11T00:00:00
db:CNNVDid:CNNVD-202108-959date:2021-08-10T00:00:00
db:NVDid:CVE-2021-38517date:2021-08-11T00:15:30.293