Buffer overflow in NETGEAR products - #VU94110

 

Buffer overflow in NETGEAR products - #VU94110

Published: July 11, 2024


Vulnerability identifier: #VU94110
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A local administrator can trigger memory corruption and cause a denial of service condition on the target system.


Affected software

RAXE500
MK72
MR70
MS70
R6700v3
RAX50
RAX41
RAX42
RAX43
MK82
MR80
MS80
MK62
MR60
MS60

Remediation

Install updates from vendor's website.

RAXE500 - update to 1.0.0.68
MK72 - update to 1.0.3.32
MR70 - update to 1.0.3.32
MS70 - update to 1.0.3.32
R6700v3 - update to 1.0.4.128
RAX50 - update to 1.0.16.132
RAX41 - update to 1.0.16.132
RAX42 - update to 1.0.16.132
RAX43 - update to 1.0.16.132
MK82 - update to 1.1.7.14
MR80 - update to 1.1.7.14
MS80 - update to 1.1.7.14
MK62 - update to 1.7.134
MR60 - update to 1.7.134
MS60 - update to 1.7.134

External References

Related Security Bulletins