CVE-2021-38517Out-of-bounds Read in Netgear R6400 Firmware

Severity
7.2HIGHNVD
CNA6.9
EPSS
0.3%
top 45.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, and XR300 before 1.0.3.50.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages4 packages

NVDnetgear/r6400_firmware< 1.0.1.70
NVDnetgear/rax75_firmware< 1.0.4.120
NVDnetgear/rax80_firmware< 1.0.4.120
NVDnetgear/xr300_firmware< 1.0.3.50

🔴Vulnerability Details

2
GHSA
GHSA-8hh6-j7m7-vh6q: Certain NETGEAR devices are affected by out-of-bounds reads and writes2022-05-24
CVEList
CVE-2021-38517: Certain NETGEAR devices are affected by out-of-bounds reads and writes2021-08-11
CVE-2021-38517 — Out-of-bounds Read in Netgear | cvebase