ID

VAR-202112-2273


CVE

CVE-2021-45676


TITLE

Netgear NETGEAR Cross-site scripting vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202112-2472

DESCRIPTION

Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126. This affects RAX200 prior to 1.0.5.126, RAX20 prior to 1.0.2.82, RAX80 prior to 1.0.5.126, RAX15 prior to 1.0.2.82, and RAX75 prior to 1.0.5.126

Trust: 0.99

sources: NVD: CVE-2021-45676 // VULMON: CVE-2021-45676

AFFECTED PRODUCTS

vendor:netgearmodel:rax15scope:ltversion:1.0.2.82

Trust: 1.0

vendor:netgearmodel:rax75scope:ltversion:1.0.5.126

Trust: 1.0

vendor:netgearmodel:rax80scope:ltversion:1.0.5.126

Trust: 1.0

vendor:netgearmodel:rax20scope:ltversion:1.0.2.82

Trust: 1.0

vendor:netgearmodel:rax200scope:ltversion:1.0.5.126

Trust: 1.0

sources: NVD: CVE-2021-45676

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2021-45676
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202112-2472
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-45676
value: LOW

Trust: 0.1

VULMON: CVE-2021-45676
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: CVE-2021-45676
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.7
impactScore: 2.7
version: 3.1

Trust: 1.0

sources: VULMON: CVE-2021-45676 // CNNVD: CNNVD-202112-2472 // NVD: CVE-2021-45676

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

sources: NVD: CVE-2021-45676

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-2472

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202112-2472

CONFIGURATIONS

sources: NVD: CVE-2021-45676

PATCH

title:Netgear NETGEAR Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=177029

Trust: 0.6

sources: CNNVD: CNNVD-202112-2472

EXTERNAL IDS

db:NVDid:CVE-2021-45676

Trust: 1.7

db:CNNVDid:CNNVD-202112-2472

Trust: 0.6

db:VULMONid:CVE-2021-45676

Trust: 0.1

sources: VULMON: CVE-2021-45676 // CNNVD: CNNVD-202112-2472 // NVD: CVE-2021-45676

REFERENCES

url:https://kb.netgear.com/000064462/security-advisory-for-stored-cross-site-scripting-on-some-routers-psv-2020-0161

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-45676

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-45676 // CNNVD: CNNVD-202112-2472 // NVD: CVE-2021-45676

SOURCES

db:VULMONid:CVE-2021-45676
db:CNNVDid:CNNVD-202112-2472
db:NVDid:CVE-2021-45676

LAST UPDATE DATE

2022-05-04T08:32:36.348000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-45676date:2022-01-05T00:00:00
db:CNNVDid:CNNVD-202112-2472date:2022-01-06T00:00:00
db:NVDid:CVE-2021-45676date:2022-01-05T13:06:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-45676date:2021-12-26T00:00:00
db:CNNVDid:CNNVD-202112-2472date:2021-12-26T00:00:00
db:NVDid:CVE-2021-45676date:2021-12-26T01:15:00