Information disclosure in NETGEAR products - #VU73742

 

Information disclosure in NETGEAR products - #VU73742

Published: March 16, 2023


Vulnerability identifier: #VU73742
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a security misconfiguration issue. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

XR1000
MK72
MR70
MS70
RAXE500
RAXE450
RAX48
RAX50S
RAX50
RAX45
RAX43
RAX42
RAX40v2
RAX35v2
RAX38v2
MS80
MR80
MK82
LAX20
MS60
MR60
MK62
NBR750
RBK752
RBR750
RBS750
RBK842
RBR840
RBS840
RBK852
RBR850
RBS850
CBR750
RBKE962
RBRE960
RBSE960

Remediation

Install updates from vendor's website.

XR1000 - update to 1.0.0.64
MK72 - update to 1.0.2.26
MR70 - update to 1.0.2.26
MS70 - update to 1.0.2.26
RAXE500 - update to 1.0.9.78
RAXE450 - update to 1.0.9.78
RAX48 - update to 1.0.10.110
RAX50S - update to 1.0.10.110
RAX50 - update to 1.0.10.110
RAX45 - update to 1.0.10.110
RAX43 - update to 1.0.10.110
RAX42 - update to 1.0.10.110
RAX40v2 - update to 1.0.10.110
RAX35v2 - update to 1.0.10.110
RAX38v2 - update to 1.0.10.110
MS80 - update to 1.1.6.14
MR80 - update to 1.1.6.14
MK82 - update to 1.1.6.14
LAX20 - update to 1.1.6.34
MS60 - update to 1.1.6.124
MR60 - update to 1.1.6.124
MK62 - update to 1.1.6.124
NBR750 - update to 4.6.5.11
RBK752 - update to 4.6.14.3
RBR750 - update to 4.6.14.3
RBS750 - update to 4.6.14.3
RBK842 - update to 4.6.14.3
RBR840 - update to 4.6.14.3
RBS840 - update to 4.6.14.3
RBK852 - update to 4.6.14.3
RBR850 - update to 4.6.14.3
RBS850 - update to 4.6.14.3
CBR750 - update to 4.6.14.4
RBKE962 - update to 6.0.3.85
RBRE960 - update to 6.0.3.85
RBSE960 - update to 6.0.3.85

External References

Related Security Bulletins