ID

VAR-202112-2226


CVE

CVE-2021-45495


TITLE

NETGEAR D7000  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2021-016964

DESCRIPTION

NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass. NETGEAR D7000 There is an unspecified vulnerability in the device.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Netgear NETGEAR D7000 is a wireless modem from Netgear. NETGEAR D7000 versions prior to 1.0.1.68 have a security vulnerability that is vulnerable to authentication bypass, and attackers can exploit this vulnerability to cause a denial of service attack

Trust: 2.25

sources: NVD: CVE-2021-45495 // JVNDB: JVNDB-2021-016964 // CNVD: CNVD-2022-06684 // VULMON: CVE-2021-45495

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-06684

AFFECTED PRODUCTS

vendor:netgearmodel:d7000scope:ltversion:1.0.1.68

Trust: 1.6

vendor:ネットギアmodel:d7000scope:eqversion:d7000 firmware 1.0.1.68

Trust: 0.8

vendor:ネットギアmodel:d7000scope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2022-06684 // JVNDB: JVNDB-2021-016964 // NVD: CVE-2021-45495

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-45495
value: CRITICAL

Trust: 1.0

cve@mitre.org: CVE-2021-45495
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-45495
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2022-06684
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202112-2285
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-45495
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-45495
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2022-06684
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-45495
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-45495
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-45495
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-06684 // VULMON: CVE-2021-45495 // JVNDB: JVNDB-2021-016964 // CNNVD: CNNVD-202112-2285 // NVD: CVE-2021-45495 // NVD: CVE-2021-45495

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-016964 // NVD: CVE-2021-45495

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-2285

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202112-2285

PATCH

title:Security Advisory for Authentication Bypass on D7000, PSV-2018-0631url:https://kb.netgear.com/000064055/Security-Advisory-for-Authentication-Bypass-on-D7000-PSV-2018-0631

Trust: 0.8

title:Patch for Netgear NETGEAR D7000 Authorization Issue Vulnerability (CNVD-2022-06684)url:https://www.cnvd.org.cn/patchInfo/show/315976

Trust: 0.6

title:Netgear NETGEAR D7000 Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=177048

Trust: 0.6

sources: CNVD: CNVD-2022-06684 // JVNDB: JVNDB-2021-016964 // CNNVD: CNNVD-202112-2285

EXTERNAL IDS

db:NVDid:CVE-2021-45495

Trust: 3.9

db:JVNDBid:JVNDB-2021-016964

Trust: 0.8

db:CNVDid:CNVD-2022-06684

Trust: 0.6

db:CNNVDid:CNNVD-202112-2285

Trust: 0.6

db:VULMONid:CVE-2021-45495

Trust: 0.1

sources: CNVD: CNVD-2022-06684 // VULMON: CVE-2021-45495 // JVNDB: JVNDB-2021-016964 // CNNVD: CNNVD-202112-2285 // NVD: CVE-2021-45495

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2021-45495

Trust: 2.0

url:https://kb.netgear.com/000064055/security-advisory-for-authentication-bypass-on-d7000-psv-2018-0631

Trust: 1.7

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-06684 // VULMON: CVE-2021-45495 // JVNDB: JVNDB-2021-016964 // CNNVD: CNNVD-202112-2285 // NVD: CVE-2021-45495

SOURCES

db:CNVDid:CNVD-2022-06684
db:VULMONid:CVE-2021-45495
db:JVNDBid:JVNDB-2021-016964
db:CNNVDid:CNNVD-202112-2285
db:NVDid:CVE-2021-45495

LAST UPDATE DATE

2024-11-23T22:29:10.412000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-06684date:2022-01-25T00:00:00
db:VULMONid:CVE-2021-45495date:2022-01-04T00:00:00
db:JVNDBid:JVNDB-2021-016964date:2022-12-27T05:20:00
db:CNNVDid:CNNVD-202112-2285date:2022-07-14T00:00:00
db:NVDid:CVE-2021-45495date:2024-11-21T06:32:20.417

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-06684date:2022-01-25T00:00:00
db:VULMONid:CVE-2021-45495date:2021-12-26T00:00:00
db:JVNDBid:JVNDB-2021-016964date:2022-12-27T00:00:00
db:CNNVDid:CNNVD-202112-2285date:2021-12-25T00:00:00
db:NVDid:CVE-2021-45495date:2021-12-26T01:15:12.640