ID

VAR-202004-1329


CVE

CVE-2017-18857


TITLE

Android and iOS for NETGEAR Insight Vulnerability in requesting weak passwords in applications

Trust: 0.8

sources: JVNDB: JVNDB-2017-014991

DESCRIPTION

The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement. (DoS) It may be put into a state. NETGEAR Insight is a cloud-based management platform from NETGEAR. The platform supports setup and configuration of NETGEAR Insight managed access points, switches and ReadyNAS devices, among others. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements

Trust: 1.8

sources: NVD: CVE-2017-18857 // JVNDB: JVNDB-2017-014991 // VULHUB: VHN-110021 // VULMON: CVE-2017-18857

AFFECTED PRODUCTS

vendor:netgearmodel:insightscope:ltversion:2.42

Trust: 1.0

vendor:netgearmodel:insightscope:eqversion:2.42

Trust: 0.8

sources: JVNDB: JVNDB-2017-014991 // NVD: CVE-2017-18857

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-18857
value: CRITICAL

Trust: 1.0

NVD: JVNDB-2017-014991
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202004-2306
value: MEDIUM

Trust: 0.6

VULHUB: VHN-110021
value: HIGH

Trust: 0.1

VULMON: CVE-2017-18857
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-18857
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2017-014991
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-110021
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-18857
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2017-014991
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-110021 // VULMON: CVE-2017-18857 // JVNDB: JVNDB-2017-014991 // CNNVD: CNNVD-202004-2306 // NVD: CVE-2017-18857

PROBLEMTYPE DATA

problemtype:CWE-521

Trust: 1.9

sources: VULHUB: VHN-110021 // JVNDB: JVNDB-2017-014991 // NVD: CVE-2017-18857

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202004-2306

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-2306

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014991

PATCH

title:Security Fix for Password Management in NETGEAR Insight App, PSV-2017-1978url:https://kb.netgear.com/000038799/Security-Fix-for-Password-Management-in-NETGEAR-Insight-App-PSV-2017-1978

Trust: 0.8

title:NETGEAR Insight Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=117745

Trust: 0.6

sources: JVNDB: JVNDB-2017-014991 // CNNVD: CNNVD-202004-2306

EXTERNAL IDS

db:NVDid:CVE-2017-18857

Trust: 2.6

db:JVNDBid:JVNDB-2017-014991

Trust: 0.8

db:CNNVDid:CNNVD-202004-2306

Trust: 0.7

db:VULHUBid:VHN-110021

Trust: 0.1

db:VULMONid:CVE-2017-18857

Trust: 0.1

sources: VULHUB: VHN-110021 // VULMON: CVE-2017-18857 // JVNDB: JVNDB-2017-014991 // CNNVD: CNNVD-202004-2306 // NVD: CVE-2017-18857

REFERENCES

url:https://kb.netgear.com/000038799/security-fix-for-password-management-in-netgear-insight-app-psv-2017-1978

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-18857

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-18857

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/521.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-110021 // VULMON: CVE-2017-18857 // JVNDB: JVNDB-2017-014991 // CNNVD: CNNVD-202004-2306 // NVD: CVE-2017-18857

SOURCES

db:VULHUBid:VHN-110021
db:VULMONid:CVE-2017-18857
db:JVNDBid:JVNDB-2017-014991
db:CNNVDid:CNNVD-202004-2306
db:NVDid:CVE-2017-18857

LAST UPDATE DATE

2024-11-23T23:07:58.766000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-110021date:2020-05-04T00:00:00
db:VULMONid:CVE-2017-18857date:2020-05-04T00:00:00
db:JVNDBid:JVNDB-2017-014991date:2020-06-01T00:00:00
db:CNNVDid:CNNVD-202004-2306date:2020-05-13T00:00:00
db:NVDid:CVE-2017-18857date:2024-11-21T03:21:06.480

SOURCES RELEASE DATE

db:VULHUBid:VHN-110021date:2020-04-28T00:00:00
db:VULMONid:CVE-2017-18857date:2020-04-28T00:00:00
db:JVNDBid:JVNDB-2017-014991date:2020-06-01T00:00:00
db:CNNVDid:CNNVD-202004-2306date:2020-04-28T00:00:00
db:NVDid:CVE-2017-18857date:2020-04-28T17:15:12.570