Information disclosure in NETGEAR products - #VU62047

 

Information disclosure in NETGEAR products - #VU62047

Published: April 11, 2022


Vulnerability identifier: #VU62047
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker on the local network can gain unauthorized access to sensitive information on the system.


Affected software

EX6130
DC112A
EX6120
EX7500
EX3700
DGN2200Bv4
RAX75
RAX200
RAX80
R7960P
R8000P
RBW30
RBS40V
D6220
D6400
DGN2200v4
WNDR3400v3
R6400
R8500
XR300
D8500
R7900
R8000
R6400v2
R7000
R7000P
RS400

Remediation

Install updates from vendor's website.

EX6130 - update to 1.0.0.44
DC112A - update to 1.0.0.52
EX6120 - update to 1.0.0.64
D6220 - update to 1.0.0.66
EX7500 - update to 1.0.0.72
EX3700 - update to 1.0.0.94
D6400 - update to 1.0.0.100
DGN2200Bv4 - update to 1.0.0.118
DGN2200v4 - update to 1.0.0.118
WNDR3400v3 - update to 1.0.1.38
R6400 - update to 1.0.1.70
R8500 - update to 1.0.2.144
XR300 - update to 1.0.3.50
D8500 - update to 1.0.3.58
RAX75 - update to 1.0.3.106
RAX200 - update to 1.0.3.106
RAX80 - update to 1.0.3.106
R7900 - update to 1.0.4.38
R8000 - update to 1.0.4.66
R6400v2 - update to 1.0.4.106
R7000 - update to 1.0.11.116
R7000P - update to 1.3.3.140
R7960P - update to 1.4.1.66
R8000P - update to 1.4.1.66
RS400 - update to 1.5.1.80
RBW30 - update to 2.6.2.2
RBS40V - update to 2.6.2.4

External References

Related Security Bulletins