CVE-2019-20710
published 2020-04-16CVE-2019-20710: Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before…
PriorityP343high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
1.29%
67.1th percentile
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | d3600_firmware | < 1.0.0.76 | 1.0.0.76 |
| netgear | d6000_firmware | < 1.0.0.76 | 1.0.0.76 |
| netgear | xr500_firmware | < 2.3.2.32 | 2.3.2.32 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wx73-f633-64gg: Certain NETGEAR devices are affected by command injection by an authenticated user
ghsa_unreviewed·2022-05-24
CVE-2019-20710 [MEDIUM] CWE-78 GHSA-wx73-f633-64gg: Certain NETGEAR devices are affected by command injection by an authenticated user
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
Red Hat
yaml-cpp: remote dos via crafted YAML file in function SingleDocParser::HandleFlowSequence
vendor_redhat·2019-01-14·CVSS 6.5
CVE-2018-20710 [MEDIUM] CWE-400 yaml-cpp: remote dos via crafted YAML file in function SingleDocParser::HandleFlowSequence
yaml-cpp: remote dos via crafted YAML file in function SingleDocParser::HandleFlowSequence
No description is available for this CVE.
Statement: This flaw was found to be a duplicate of CVE-2019-6285. Please see https://access.redhat.com/security/cve/CVE-2019-6285 for information about affected products and security errata.
Package: yaml-cpp (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: yaml-cpp (Red Hat OpenStack Platform 13 (Queens)) - Not affected
Package: yaml-cpp (Red Hat OpenStack Platform 14 (Rocky)) - Not affected
Package: yaml-cpp (Red Hat OpenStack Platform 8 (Liberty)) - Not affected
Package: yaml-cpp (Red Hat OpenStack Platform 9 (Mitaka)) - Not affected
Package: yaml-cpp (Red Hat Satellite 6) - Not affected
Package: rh-mongodb32-yaml-cpp (Red Hat Sof
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-16
Published