ID

VAR-202112-2225


CVE

CVE-2021-45496


TITLE

NETGEAR D7000  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2021-016965

DESCRIPTION

NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass. NETGEAR D7000 There is an unspecified vulnerability in the device.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. NETGEAR D7000 and NETGEAR are both products of Netgear Corporation. The NETGEAR D7000 is a wireless modem. NETGEAR is a router. A hardware device that connects two or more networks and acts as a gateway between the networks. There is a security vulnerability in NETGEAR D7000 versions prior to 1.0.1.82

Trust: 2.25

sources: NVD: CVE-2021-45496 // JVNDB: JVNDB-2021-016965 // CNVD: CNVD-2022-06685 // VULMON: CVE-2021-45496

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-06685

AFFECTED PRODUCTS

vendor:netgearmodel:d7000scope:ltversion:1.0.1.82

Trust: 1.6

vendor:ネットギアmodel:d7000scope:eqversion:d7000 firmware 1.0.1.82

Trust: 0.8

vendor:ネットギアmodel:d7000scope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2022-06685 // JVNDB: JVNDB-2021-016965 // NVD: CVE-2021-45496

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-45496
value: CRITICAL

Trust: 1.0

cve@mitre.org: CVE-2021-45496
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-45496
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2022-06685
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202112-2282
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-45496
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-45496
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2022-06685
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-45496
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-45496
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2021-45496
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-06685 // VULMON: CVE-2021-45496 // JVNDB: JVNDB-2021-016965 // CNNVD: CNNVD-202112-2282 // NVD: CVE-2021-45496 // NVD: CVE-2021-45496

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-016965 // NVD: CVE-2021-45496

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-2282

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202112-2282

PATCH

title:Security Advisory for Authentication Bypass on D7000, PSV-2021-0060url:https://kb.netgear.com/000064529/Security-Advisory-for-Authentication-Bypass-on-D7000-PSV-2021-0060

Trust: 0.8

title:Patch for NETGEAR D7000 and NETGEAR Authorization Issue Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/315971

Trust: 0.6

title:Netgear NETGEAR D7000 and NETGEAR Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=177047

Trust: 0.6

sources: CNVD: CNVD-2022-06685 // JVNDB: JVNDB-2021-016965 // CNNVD: CNNVD-202112-2282

EXTERNAL IDS

db:NVDid:CVE-2021-45496

Trust: 3.9

db:JVNDBid:JVNDB-2021-016965

Trust: 0.8

db:CNVDid:CNVD-2022-06685

Trust: 0.6

db:CNNVDid:CNNVD-202112-2282

Trust: 0.6

db:VULMONid:CVE-2021-45496

Trust: 0.1

sources: CNVD: CNVD-2022-06685 // VULMON: CVE-2021-45496 // JVNDB: JVNDB-2021-016965 // CNNVD: CNNVD-202112-2282 // NVD: CVE-2021-45496

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2021-45496

Trust: 2.0

url:https://kb.netgear.com/000064529/security-advisory-for-authentication-bypass-on-d7000-psv-2021-0060

Trust: 1.7

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-06685 // VULMON: CVE-2021-45496 // JVNDB: JVNDB-2021-016965 // CNNVD: CNNVD-202112-2282 // NVD: CVE-2021-45496

SOURCES

db:CNVDid:CNVD-2022-06685
db:VULMONid:CVE-2021-45496
db:JVNDBid:JVNDB-2021-016965
db:CNNVDid:CNNVD-202112-2282
db:NVDid:CVE-2021-45496

LAST UPDATE DATE

2024-11-23T23:00:59.754000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-06685date:2022-01-25T00:00:00
db:VULMONid:CVE-2021-45496date:2022-01-04T00:00:00
db:JVNDBid:JVNDB-2021-016965date:2022-12-27T05:22:00
db:CNNVDid:CNNVD-202112-2282date:2022-07-14T00:00:00
db:NVDid:CVE-2021-45496date:2024-11-21T06:32:20.567

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-06685date:2022-01-25T00:00:00
db:VULMONid:CVE-2021-45496date:2021-12-26T00:00:00
db:JVNDBid:JVNDB-2021-016965date:2022-12-27T00:00:00
db:CNNVDid:CNNVD-202112-2282date:2021-12-25T00:00:00
db:NVDid:CVE-2021-45496date:2021-12-26T01:15:12.687