CVE-2019-20685
published 2020-04-16CVE-2019-20685: Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.75, D6000 before…
PriorityP349high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.56%
43.2th percentile
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6200 before 1.1.00.32, D7000 before 1.0.1.68, DM200 before 1.0.0.58, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | d3600_firmware | < 1.0.0.75 | 1.0.0.75 |
| netgear | d6000_firmware | < 1.0.0.75 | 1.0.0.75 |
| netgear | d6200_firmware | < 1.1.00.32 | 1.1.00.32 |
| netgear | d7000_firmware | < 1.0.1.68 | 1.0.1.68 |
| netgear | dm200_firmware | < 1.0.0.58 | 1.0.0.58 |
| netgear | jr6150_firmware | < 1.0.1.18 | 1.0.1.18 |
| netgear | pr2000_firmware | < 1.0.0.28 | 1.0.0.28 |
| netgear | r6020_firmware | < 1.0.0.38 | 1.0.0.38 |
| netgear | r6050_firmware | < 1.0.1.18 | 1.0.1.18 |
| netgear | r6080_firmware | < 1.0.0.38 | 1.0.0.38 |
| netgear | r6120_firmware | < 1.0.0.46 | 1.0.0.46 |
| netgear | r6220_firmware | < 1.1.0.80 | 1.1.0.80 |
| netgear | r6260_firmware | < 1.1.0.40 | 1.1.0.40 |
| netgear | r6700_firmware | < 1.2.0.36 | 1.2.0.36 |
| netgear | r6800_firmware | < 1.2.0.36 | 1.2.0.36 |
| netgear | r6900_firmware | < 1.2.0.36 | 1.2.0.36 |
| netgear | wnr2020_firmware | < 1.1.0.62 | 1.1.0.62 |
| netgear | xr500_firmware | < 2.3.2.32 | 2.3.2.32 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5hmf-9xw5-54xx: Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker
ghsa_unreviewed·2022-05-24
CVE-2019-20685 [MEDIUM] GHSA-5hmf-9xw5-54xx: Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6200 before 1.1.00.32, D7000 before 1.0.1.68, DM200 before 1.0.0.58, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.
Red Hat
netkit-rsh: rcp access restriction bypass
vendor_redhat·2021-11-19·CVSS 5.3
CVE-2019-7282 [MEDIUM] CWE-281 netkit-rsh: rcp access restriction bypass
netkit-rsh: rcp access restriction bypass
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
A vulnerability was found in rsh. The vulnerability occurs due to bypass restrictions via the filename of [.] or an empty filename. This flaw allows an attacker to modify the permissions of the target directory on the client-side.
Statement: Red Hat Enterprise Linux 6 and 7 were affected but Out of Support Scope.
https://access.redhat.com/support/policy/updates/errata/
Package: rsh (Red Hat Enterprise Linux 6) - Out of support scope
Package: rsh (Red Hat Enterprise Linux 7
Red Hat
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
vendor_redhat·2021-02-02·CVSS 5.3
CVE-2019-25018 [MEDIUM] CWE-863 krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Package: krb5-appl (Red Hat Enterprise Linux 6) - Out of support scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-16
Published