ID

VAR-202004-0888


CVE

CVE-2019-20648


TITLE

NETGEAR RAX40 input validation error vulnerability

Trust: 1.2

sources: CNVD: CNVD-2020-26949 // CNNVD: CNNVD-202004-1238

DESCRIPTION

NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings. NETGEAR RN42400 The device contains an input verification vulnerability.Information may be tampered with. NETGEAR RAX40 is a wireless router of NETGEAR. There is currently no detailed vulnerability details provided

Trust: 2.16

sources: NVD: CVE-2019-20648 // JVNDB: JVNDB-2019-015448 // CNVD: CNVD-2020-26949

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-26949

AFFECTED PRODUCTS

vendor:netgearmodel:rn42400scope:ltversion:6.10.2

Trust: 1.6

vendor:netgearmodel:rn42400scope:eqversion:6.10.2

Trust: 0.8

sources: CNVD: CNVD-2020-26949 // JVNDB: JVNDB-2019-015448 // NVD: CVE-2019-20648

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-20648
value: LOW

Trust: 1.0

cve@mitre.org: CVE-2019-20648
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2019-015448
value: LOW

Trust: 0.8

CNVD: CNVD-2020-26949
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202004-1238
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2019-20648
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:N/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2019-015448
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:N/I:P/A:N
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-26949
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-20648
baseSeverity: LOW
baseScore: 3.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 1.4
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2019-20648
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 2.5
version: 3.0

Trust: 1.0

NVD: JVNDB-2019-015448
baseSeverity: LOW
baseScore: 3.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-26949 // JVNDB: JVNDB-2019-015448 // CNNVD: CNNVD-202004-1238 // NVD: CVE-2019-20648 // NVD: CVE-2019-20648

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-20

Trust: 0.8

sources: JVNDB: JVNDB-2019-015448 // NVD: CVE-2019-20648

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202004-1238

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202004-1238

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-015448

PATCH

title:Security Advisory for Security Misconfiguration on RN42400, PSV-2019-0205url:https://kb.netgear.com/000061494/Security-Advisory-for-Security-Misconfiguration-on-RN42400-PSV-2019-0205

Trust: 0.8

title:Patch for NETGEAR RAX40 input validation error vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/216393

Trust: 0.6

title:NETGEAR RAX40 Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116874

Trust: 0.6

sources: CNVD: CNVD-2020-26949 // JVNDB: JVNDB-2019-015448 // CNNVD: CNNVD-202004-1238

EXTERNAL IDS

db:NVDid:CVE-2019-20648

Trust: 3.0

db:JVNDBid:JVNDB-2019-015448

Trust: 0.8

db:CNVDid:CNVD-2020-26949

Trust: 0.6

db:CNNVDid:CNNVD-202004-1238

Trust: 0.6

sources: CNVD: CNVD-2020-26949 // JVNDB: JVNDB-2019-015448 // CNNVD: CNNVD-202004-1238 // NVD: CVE-2019-20648

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-20648

Trust: 2.0

url:https://kb.netgear.com/000061494/security-advisory-for-security-misconfiguration-on-rn42400-psv-2019-0205

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-20648

Trust: 0.8

sources: CNVD: CNVD-2020-26949 // JVNDB: JVNDB-2019-015448 // CNNVD: CNNVD-202004-1238 // NVD: CVE-2019-20648

SOURCES

db:CNVDid:CNVD-2020-26949
db:JVNDBid:JVNDB-2019-015448
db:CNNVDid:CNNVD-202004-1238
db:NVDid:CVE-2019-20648

LAST UPDATE DATE

2024-11-23T22:48:02.033000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-26949date:2020-05-07T00:00:00
db:JVNDBid:JVNDB-2019-015448date:2020-05-20T00:00:00
db:CNNVDid:CNNVD-202004-1238date:2020-04-26T00:00:00
db:NVDid:CVE-2019-20648date:2024-11-21T04:38:57.910

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-26949date:2020-05-07T00:00:00
db:JVNDBid:JVNDB-2019-015448date:2020-05-20T00:00:00
db:CNNVDid:CNNVD-202004-1238date:2020-04-15T00:00:00
db:NVDid:CVE-2019-20648date:2020-04-15T18:15:14.613