Stack-based buffer overflow in NETGEAR products - #VU85062

 

Stack-based buffer overflow in NETGEAR products - #VU85062

Published: January 8, 2024


Vulnerability identifier: #VU85062
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A local administrator attacker can trigger stack-based buffer overflow and cause a denial of service condition on the target system.


Affected software

RAXE450
RAXE500
RAX42
RAX50S
RAX40v2
RAX45
RAX35v2
RAX50
RAX43
RAX38v2
RAX48
MR60
MS60
MK62
MS80
MK82
MR80
RBR750
RBK842
RBS840
RBR840
RBK852
RBS850
RBR850
RBK752
RBS750
CBR750
MK72
MR70
MS70
RBRE960
RBSE960
RBKE962

Remediation

Install updates from vendor's website.

RAXE450 - update to 1.0.10.82
RAXE500 - update to 1.0.10.82
RAX42 - update to 1.0.11.112
RAX50S - update to 1.0.11.112
RAX40v2 - update to 1.0.11.112
RAX45 - update to 1.0.11.112
RAX35v2 - update to 1.0.11.112
RAX50 - update to 1.0.11.112
RAX43 - update to 1.0.11.112
RAX38v2 - update to 1.0.11.112
RAX48 - update to 1.0.11.112
MR60 - update to 1.1.6.124
MS60 - update to 1.1.6.124
MK62 - update to 1.1.6.124
MS80 - update to 1.1.7.12
MK82 - update to 1.1.7.12
MR80 - update to 1.1.7.12
RBR750 - update to 4.6.9.11
RBK842 - update to 4.6.9.11
RBS840 - update to 4.6.9.11
RBR840 - update to 4.6.9.11
RBK852 - update to 4.6.9.11
RBS850 - update to 4.6.9.11
RBR850 - update to 4.6.9.11
RBK752 - update to 4.6.9.11
RBS750 - update to 4.6.9.11
CBR750 - update to 4.6.14.4
MK72 - update to 7.0.2.26
MR70 - update to 7.0.2.26
MS70 - update to 7.0.2.26
RBRE960 - update to 7.2.6.21
RBSE960 - update to 7.2.6.21
RBKE962 - update to 7.2.6.21

External References

Related Security Bulletins