ID

VAR-202004-1373


CVE

CVE-2017-18808


TITLE

NETGEAR ReadyNAS OS 6 Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2017-014894

DESCRIPTION

NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings. NETGEAR ReadyNAS OS 6 An unspecified vulnerability exists in the device.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements

Trust: 1.71

sources: NVD: CVE-2017-18808 // JVNDB: JVNDB-2017-014894 // VULHUB: VHN-109967

AFFECTED PRODUCTS

vendor:netgearmodel:readynas osscope:ltversion:6.8.0

Trust: 1.0

vendor:netgearmodel:readynas osscope:gteversion:6.0

Trust: 1.0

vendor:netgearmodel:readynas osscope:eqversion:6.8.0

Trust: 0.8

sources: JVNDB: JVNDB-2017-014894 // NVD: CVE-2017-18808

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-18808
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2017-18808
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2017-014894
value: MEDIUM

Trust: 0.8

VULHUB: VHN-109967
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-18808
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2017-014894
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-109967
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-18808
baseSeverity: MEDIUM
baseScore: 4.2
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 0.8
impactScore: 3.4
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2017-18808
baseSeverity: MEDIUM
baseScore: 4.2
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 0.8
impactScore: 3.4
version: 3.0

Trust: 1.0

NVD: JVNDB-2017-014894
baseSeverity: MEDIUM
baseScore: 4.2
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-109967 // JVNDB: JVNDB-2017-014894 // NVD: CVE-2017-18808 // NVD: CVE-2017-18808

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2017-18808

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-1817

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014894

PATCH

title:Security Advisory for Security Misconfiguration Vulnerability on Some ReadyNAS Devices, PSV-2017-2000url:https://kb.netgear.com/000049057/Security-Advisory-for-Security-Misconfiguration-Vulnerability-on-Some-ReadyNAS-Devices-PSV-2017-2000

Trust: 0.8

title:NETGEAR ReadyNAS OS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116294

Trust: 0.6

sources: JVNDB: JVNDB-2017-014894 // CNNVD: CNNVD-202004-1817

EXTERNAL IDS

db:NVDid:CVE-2017-18808

Trust: 2.5

db:JVNDBid:JVNDB-2017-014894

Trust: 0.8

db:CNNVDid:CNNVD-202004-1817

Trust: 0.7

db:VULHUBid:VHN-109967

Trust: 0.1

sources: VULHUB: VHN-109967 // JVNDB: JVNDB-2017-014894 // CNNVD: CNNVD-202004-1817 // NVD: CVE-2017-18808

REFERENCES

url:https://kb.netgear.com/000049057/security-advisory-for-security-misconfiguration-vulnerability-on-some-readynas-devices-psv-2017-2000

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2017-18808

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-18808

Trust: 0.8

sources: VULHUB: VHN-109967 // JVNDB: JVNDB-2017-014894 // CNNVD: CNNVD-202004-1817 // NVD: CVE-2017-18808

SOURCES

db:VULHUBid:VHN-109967
db:JVNDBid:JVNDB-2017-014894
db:CNNVDid:CNNVD-202004-1817
db:NVDid:CVE-2017-18808

LAST UPDATE DATE

2024-11-23T21:59:20.447000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-109967date:2020-04-23T00:00:00
db:JVNDBid:JVNDB-2017-014894date:2020-05-20T00:00:00
db:CNNVDid:CNNVD-202004-1817date:2020-04-22T00:00:00
db:NVDid:CVE-2017-18808date:2024-11-21T03:20:58.780

SOURCES RELEASE DATE

db:VULHUBid:VHN-109967date:2020-04-21T00:00:00
db:JVNDBid:JVNDB-2017-014894date:2020-05-20T00:00:00
db:CNNVDid:CNNVD-202004-1817date:2020-04-21T00:00:00
db:NVDid:CVE-2017-18808date:2020-04-21T16:15:51.507