ID

VAR-202112-2301


CVE

CVE-2021-45648


TITLE

plural  NETGEAR  Device information disclosure vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2021-017540

DESCRIPTION

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6150v2 before 1.0.1.106, EX6250 before 1.0.0.146, EX6400 before 1.0.2.164, EX6400v2 before 1.0.0.146, EX6410 before 1.0.0.146, EX6420 before 1.0.0.146, EX7300 before 1.0.2.164, EX7300v2 before 1.0.0.146, EX7320 before 1.0.0.146, EX7700 before 1.0.0.222, LBR1020 before 2.6.5.16, LBR20 before 2.6.5.2, RBK352 before 4.3.4.7, RBK50 before 2.7.3.22, RBR350 before 4.3.4.7, RBR50 before 2.7.3.22, and RBS350 before 4.3.4.7. This affects EX6100v2 prior to 1.0.1.106, EX6150v2 prior to 1.0.1.106, EX6250 prior to 1.0.0.146, EX6400 prior to 1.0.2.164, EX6400v2 prior to 1.0.0.146, EX6410 prior to 1.0.0.146, EX6420 prior to 1.0.0.146, EX7300 prior to 1.0.2.164, EX7300v2 prior to 1.0.0.146, EX7320 prior to 1.0.0.146, EX7700 prior to 1.0.0.222, LBR1020 prior to 2.6.5.16, LBR20 prior to 2.6.5.2, RBK352 prior to 4.3.4.7, RBK50 prior to 2.7.3.22, RBR350 prior to 4.3.4.7, RBR50 prior to 2.7.3.22, and RBS350 prior to 4.3.4.7

Trust: 1.71

sources: NVD: CVE-2021-45648 // JVNDB: JVNDB-2021-017540 // VULMON: CVE-2021-45648

AFFECTED PRODUCTS

vendor:netgearmodel:ex6420scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:ex6410scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:ex7300v2scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:ex7320scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:lbr1020scope:ltversion:2.6.5.16

Trust: 1.0

vendor:netgearmodel:rbk50scope:ltversion:2.7.3.22

Trust: 1.0

vendor:netgearmodel:rbs350scope:ltversion:4.3.4.7

Trust: 1.0

vendor:netgearmodel:ex7300scope:ltversion:1.0.2.164

Trust: 1.0

vendor:netgearmodel:ex6400v2scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:ex7700scope:ltversion:1.0.0.222

Trust: 1.0

vendor:netgearmodel:rbk352scope:ltversion:4.3.4.7

Trust: 1.0

vendor:netgearmodel:rbr350scope:ltversion:4.3.4.7

Trust: 1.0

vendor:netgearmodel:ex6100v2scope:ltversion:1.0.1.106

Trust: 1.0

vendor:netgearmodel:ex6400scope:ltversion:1.0.2.164

Trust: 1.0

vendor:netgearmodel:rbr50scope:ltversion:2.7.3.22

Trust: 1.0

vendor:netgearmodel:lbr20scope:ltversion:2.6.5.2

Trust: 1.0

vendor:netgearmodel:ex6250scope:ltversion:1.0.0.146

Trust: 1.0

vendor:netgearmodel:ex6150v2scope:ltversion:1.0.1.106

Trust: 1.0

vendor:ネットギアmodel:ex7300v2scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex7320scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6420scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6150v2scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6100v2scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex7300scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6400v2scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6250scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6400scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:ex6410scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-017540 // NVD: CVE-2021-45648

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-45648
value: HIGH

Trust: 1.0

cve@mitre.org: CVE-2021-45648
value: LOW

Trust: 1.0

NVD: CVE-2021-45648
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202112-2444
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-45648
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-45648
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2021-45648
baseSeverity: LOW
baseScore: 3.1
vectorString: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.6
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2021-45648
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-017540 // CNNVD: CNNVD-202112-2444 // NVD: CVE-2021-45648 // NVD: CVE-2021-45648

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.0

problemtype:information leak (CWE-200) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-017540 // NVD: CVE-2021-45648

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-2444

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202112-2444

PATCH

title:Security Advisory for Sensitive Information Disclosure on Some Routers, Extenders, and WiFi Systems, PSV-2020-0453url:https://kb.netgear.com/000064494/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-Extenders-and-WiFi-Systems-PSV-2020-0453

Trust: 0.8

title:Netgear NETGEAR Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=176206

Trust: 0.6

sources: JVNDB: JVNDB-2021-017540 // CNNVD: CNNVD-202112-2444

EXTERNAL IDS

db:NVDid:CVE-2021-45648

Trust: 3.3

db:JVNDBid:JVNDB-2021-017540

Trust: 0.8

db:CNNVDid:CNNVD-202112-2444

Trust: 0.6

db:VULMONid:CVE-2021-45648

Trust: 0.1

sources: VULMON: CVE-2021-45648 // JVNDB: JVNDB-2021-017540 // CNNVD: CNNVD-202112-2444 // NVD: CVE-2021-45648

REFERENCES

url:https://kb.netgear.com/000064494/security-advisory-for-sensitive-information-disclosure-on-some-routers-extenders-and-wifi-systems-psv-2020-0453

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-45648

Trust: 0.8

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-45648 // JVNDB: JVNDB-2021-017540 // CNNVD: CNNVD-202112-2444 // NVD: CVE-2021-45648

SOURCES

db:VULMONid:CVE-2021-45648
db:JVNDBid:JVNDB-2021-017540
db:CNNVDid:CNNVD-202112-2444
db:NVDid:CVE-2021-45648

LAST UPDATE DATE

2024-11-23T22:54:44.943000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-45648date:2021-12-27T00:00:00
db:JVNDBid:JVNDB-2021-017540date:2023-01-25T01:50:00
db:CNNVDid:CNNVD-202112-2444date:2022-01-11T00:00:00
db:NVDid:CVE-2021-45648date:2024-11-21T06:32:46.740

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-45648date:2021-12-26T00:00:00
db:JVNDBid:JVNDB-2021-017540date:2023-01-25T00:00:00
db:CNNVDid:CNNVD-202112-2444date:2021-12-26T00:00:00
db:NVDid:CVE-2021-45648date:2021-12-26T01:15:20.010