Buffer overflow in NETGEAR products - #VU73746

 

Buffer overflow in NETGEAR products - #VU73746

Published: March 16, 2023


Vulnerability identifier: #VU73746
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A remote attacker on the local network can trigger memory corruption and cause a denial of service condition on the target system.


Affected software

R6400
R6400v2
R7000
R7000P
RS400
R6700v3
RAX200
RAX75
RAX80
LAX20
MK62
MR60
MS60
CBR40
RBW30

Remediation

Install updates from vendor's website.

R6400 - update to 1.0.1.70
R6400v2 - update to 1.0.4.118
R6700v3 - update to 1.0.4.118
RAX200 - update to 1.0.4.120
RAX75 - update to 1.0.4.120
RAX80 - update to 1.0.4.120
R7000 - update to 1.0.11.130
LAX20 - update to 1.1.6.34
MK62 - update to 1.1.6.122
MR60 - update to 1.1.6.122
MS60 - update to 1.1.6.122
R7000P - update to 1.3.3.148
RS400 - update to 1.5.1.86
CBR40 - update to 2.5.0.24
RBW30 - update to 2.6.2.6

External References

Related Security Bulletins