CVE-2019-20679
published 2020-04-15CVE-2019-20679: NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.28%
66.7th percentile
NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | mr1100_firmware | < 12.06.08.00 | 12.06.08.00 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.3HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mp8-4qmg-75h8: NETGEAR MR1100 devices before 12
ghsa_unreviewed·2022-05-24
CVE-2019-20679 [HIGH] CWE-20 GHSA-5mp8-4qmg-75h8: NETGEAR MR1100 devices before 12
NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.
Red Hat
busybox: Out of bounds read in udhcp components resulting in information disclosure
vendor_redhat·2019-01-09·CVSS 7.5
CVE-2019-5747 [HIGH] CWE-125 busybox: Out of bounds read in udhcp components resulting in information disclosure
busybox: Out of bounds read in udhcp components resulting in information disclosure
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to assurance of a 4-byte length when decoding DHCP_SUBNET. NOTE: this issue exists because of an incomplete fix for CVE-2018-20679.
Statement: This issue did not affect the versions of busybox as shipped with Red Hat Enterprise Linux 5 and 6.
Package: busybox (Red Hat Enterprise Linux 5) - Not affected
Package: busybox (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
2020-04-15
Published