ID

VAR-202108-1659


CVE

CVE-2021-38532


TITLE

NETGEAR WAC104  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2021-010448

DESCRIPTION

NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings. NETGEAR WAC104 There is an unspecified vulnerability in the device.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2021-38532 // JVNDB: JVNDB-2021-010448 // VULMON: CVE-2021-38532

AFFECTED PRODUCTS

vendor:netgearmodel:wac104scope:ltversion:1.0.4.15

Trust: 1.0

vendor:ネットギアmodel:wac104scope:eqversion: -

Trust: 0.8

vendor:ネットギアmodel:wac104scope:eqversion:wac104 firmware 1.0.4.15

Trust: 0.8

sources: JVNDB: JVNDB-2021-010448 // NVD: CVE-2021-38532

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-38532
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2021-38532
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-38532
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202108-947
value: HIGH

Trust: 0.6

VULMON: CVE-2021-38532
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-38532
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-38532
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-38532
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-38532
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-38532 // JVNDB: JVNDB-2021-010448 // CNNVD: CNNVD-202108-947 // NVD: CVE-2021-38532 // NVD: CVE-2021-38532

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-010448 // NVD: CVE-2021-38532

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-947

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202108-947

PATCH

title:Security Advisory for Security Misconfiguration on WAC104, PSV-2021-0124url:https://kb.netgear.com/000063787/Security-Advisory-for-Security-Misconfiguration-on-WAC104-PSV-2021-0124

Trust: 0.8

title:Netgear NETGEAR and NETGEAR WAC104 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159341

Trust: 0.6

sources: JVNDB: JVNDB-2021-010448 // CNNVD: CNNVD-202108-947

EXTERNAL IDS

db:NVDid:CVE-2021-38532

Trust: 3.3

db:JVNDBid:JVNDB-2021-010448

Trust: 0.8

db:CNNVDid:CNNVD-202108-947

Trust: 0.6

db:VULMONid:CVE-2021-38532

Trust: 0.1

sources: VULMON: CVE-2021-38532 // JVNDB: JVNDB-2021-010448 // CNNVD: CNNVD-202108-947 // NVD: CVE-2021-38532

REFERENCES

url:https://kb.netgear.com/000063787/security-advisory-for-security-misconfiguration-on-wac104-psv-2021-0124

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-38532

Trust: 1.4

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-38532 // JVNDB: JVNDB-2021-010448 // CNNVD: CNNVD-202108-947 // NVD: CVE-2021-38532

SOURCES

db:VULMONid:CVE-2021-38532
db:JVNDBid:JVNDB-2021-010448
db:CNNVDid:CNNVD-202108-947
db:NVDid:CVE-2021-38532

LAST UPDATE DATE

2024-08-14T15:06:45.354000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-38532date:2021-08-19T00:00:00
db:JVNDBid:JVNDB-2021-010448date:2022-07-01T06:12:00
db:CNNVDid:CNNVD-202108-947date:2021-08-26T00:00:00
db:NVDid:CVE-2021-38532date:2021-08-19T12:38:47.213

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-38532date:2021-08-11T00:00:00
db:JVNDBid:JVNDB-2021-010448date:2022-07-01T00:00:00
db:CNNVDid:CNNVD-202108-947date:2021-08-10T00:00:00
db:NVDid:CVE-2021-38532date:2021-08-11T00:17:12.687