ID

VAR-202002-0805


CVE

CVE-2014-3919


TITLE

Netgear CG3100 Cross-site scripting vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2014-008910

DESCRIPTION

A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information. Netgear CG3100 A cross-site scripting vulnerability exists in the device.Information may be obtained and tampered with. The NETGEAR CG3100 Wireless Gigabit Gateway provides the ultimate in network performance for home and small businesses. NETGEAR CG3100 '/goform/VooControle' has a cross-site request forgery vulnerability, HTTP send request / goform / VooControle does not require multiple steps, explicit confirmation, or unique tags when performing sensitive operations. Allows context-sensitive attackers to initiate cross-site request forgery attacks by enticing users to use specially crafted links

Trust: 2.16

sources: NVD: CVE-2014-3919 // JVNDB: JVNDB-2014-008910 // CNVD: CNVD-2014-03941

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03941

AFFECTED PRODUCTS

vendor:netgearmodel:cg3100scope:ltversion:3.9.2421.13.mp3.v0027

Trust: 1.0

vendor:netgearmodel:cg3100scope:eqversion:3.9.2421.13.mp3 v0027

Trust: 0.8

vendor:netgearmodel:cg3100 3.9.21.13.mp3.v0022scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-03941 // JVNDB: JVNDB-2014-008910 // NVD: CVE-2014-3919

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3919
value: CRITICAL

Trust: 1.0

NVD: JVNDB-2014-008910
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2014-03941
value: LOW

Trust: 0.6

CNNVD: CNNVD-202002-769
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2014-3919
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2014-008910
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2014-03941
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2014-3919
baseSeverity: CRITICAL
baseScore: 9.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 5.8
version: 3.1

Trust: 1.0

NVD: JVNDB-2014-008910
baseSeverity: CRITICAL
baseScore: 9.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2014-03941 // JVNDB: JVNDB-2014-008910 // CNNVD: CNNVD-202002-769 // NVD: CVE-2014-3919

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2014-008910 // NVD: CVE-2014-3919

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202002-769

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202002-769

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008910

PATCH

title:Top Pageurl:https://www.netgear.com/

Trust: 0.8

title:NETGEAR CG3100 '/goform/VooControle' patch for cross-site request forgery vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/46858

Trust: 0.6

title:Netgear CG3100 Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=110114

Trust: 0.6

sources: CNVD: CNVD-2014-03941 // JVNDB: JVNDB-2014-008910 // CNNVD: CNNVD-202002-769

EXTERNAL IDS

db:NVDid:CVE-2014-3919

Trust: 3.0

db:JVNDBid:JVNDB-2014-008910

Trust: 0.8

db:OSVDBid:107685

Trust: 0.6

db:CNVDid:CNVD-2014-03941

Trust: 0.6

db:CNNVDid:CNNVD-202002-769

Trust: 0.6

sources: CNVD: CNVD-2014-03941 // JVNDB: JVNDB-2014-008910 // CNNVD: CNNVD-202002-769 // NVD: CVE-2014-3919

REFERENCES

url:http://softage.be/netgear/

Trust: 2.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3919

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2014-3919

Trust: 0.8

url:http://www.osvdb.com/show/osvdb/107685

Trust: 0.6

sources: CNVD: CNVD-2014-03941 // JVNDB: JVNDB-2014-008910 // CNNVD: CNNVD-202002-769 // NVD: CVE-2014-3919

SOURCES

db:CNVDid:CNVD-2014-03941
db:JVNDBid:JVNDB-2014-008910
db:CNNVDid:CNNVD-202002-769
db:NVDid:CVE-2014-3919

LAST UPDATE DATE

2024-11-23T22:44:43.948000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03941date:2014-06-30T00:00:00
db:JVNDBid:JVNDB-2014-008910date:2020-03-03T00:00:00
db:CNNVDid:CNNVD-202002-769date:2021-01-05T00:00:00
db:NVDid:CVE-2014-3919date:2024-11-21T02:09:07.683

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03941date:2014-06-30T00:00:00
db:JVNDBid:JVNDB-2014-008910date:2020-03-03T00:00:00
db:CNNVDid:CNNVD-202002-769date:2020-02-13T00:00:00
db:NVDid:CVE-2014-3919date:2020-02-13T19:15:11.647