ID

VAR-202004-1646


CVE

CVE-2018-21159


TITLE

NETGEAR ReadyNAS Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-016391

DESCRIPTION

NETGEAR ReadyNAS devices before 6.9.3 are affected by incorrect configuration of security settings. NETGEAR ReadyNAS An unspecified vulnerability exists in the device.Information may be tampered with. NETGEAR ReadyNAS OS is an operating system for ReadyNAS network-attached storage devices developed by NETGEAR. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements

Trust: 1.8

sources: NVD: CVE-2018-21159 // JVNDB: JVNDB-2018-016391 // VULHUB: VHN-132037 // VULMON: CVE-2018-21159

AFFECTED PRODUCTS

vendor:netgearmodel:readynas osscope:gteversion:6.0

Trust: 1.0

vendor:netgearmodel:readynas osscope:ltversion:6.9.3

Trust: 1.0

vendor:netgearmodel:readynas osscope:eqversion:6.9.3

Trust: 0.8

vendor:netgearmodel:readynas osscope:eqversion:6.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.0.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.0.2

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.1.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.2.4

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.4.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.4.2

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.5.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.5.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.5.2

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.6.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.6.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.7.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.7.2

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.7.4

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.7.5

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.8.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.8.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.9.0

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.9.1

Trust: 0.1

vendor:netgearmodel:readynas osscope:eqversion:6.9.2

Trust: 0.1

sources: VULMON: CVE-2018-21159 // JVNDB: JVNDB-2018-016391 // NVD: CVE-2018-21159

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-21159
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2018-21159
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2018-016391
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202004-2208
value: MEDIUM

Trust: 0.6

VULHUB: VHN-132037
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-21159
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-21159
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2018-016391
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-132037
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-21159
baseSeverity: MEDIUM
baseScore: 4.9
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.2
impactScore: 3.6
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2018-21159
baseSeverity: MEDIUM
baseScore: 4.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.0

Trust: 1.0

NVD: JVNDB-2018-016391
baseSeverity: MEDIUM
baseScore: 4.9
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-132037 // VULMON: CVE-2018-21159 // JVNDB: JVNDB-2018-016391 // CNNVD: CNNVD-202004-2208 // NVD: CVE-2018-21159 // NVD: CVE-2018-21159

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2018-21159

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202004-2208

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-2208

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-016391

PATCH

title:Security Advisory for Security Misconfiguration on ReadyNAS OS 6, PSV-2017-1999url:https://kb.netgear.com/000059471/Security-Advisory-for-Security-Misconfiguration-on-ReadyNAS-OS-6-PSV-2017-1999

Trust: 0.8

title:NETGEAR ReadyNAS OS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=117303

Trust: 0.6

sources: JVNDB: JVNDB-2018-016391 // CNNVD: CNNVD-202004-2208

EXTERNAL IDS

db:NVDid:CVE-2018-21159

Trust: 2.6

db:JVNDBid:JVNDB-2018-016391

Trust: 0.8

db:CNNVDid:CNNVD-202004-2208

Trust: 0.7

db:VULHUBid:VHN-132037

Trust: 0.1

db:VULMONid:CVE-2018-21159

Trust: 0.1

sources: VULHUB: VHN-132037 // VULMON: CVE-2018-21159 // JVNDB: JVNDB-2018-016391 // CNNVD: CNNVD-202004-2208 // NVD: CVE-2018-21159

REFERENCES

url:https://kb.netgear.com/000059471/security-advisory-for-security-misconfiguration-on-readynas-os-6-psv-2017-1999

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-21159

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-21159

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-132037 // VULMON: CVE-2018-21159 // JVNDB: JVNDB-2018-016391 // CNNVD: CNNVD-202004-2208 // NVD: CVE-2018-21159

SOURCES

db:VULHUBid:VHN-132037
db:VULMONid:CVE-2018-21159
db:JVNDBid:JVNDB-2018-016391
db:CNNVDid:CNNVD-202004-2208
db:NVDid:CVE-2018-21159

LAST UPDATE DATE

2024-11-23T21:59:20.115000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-132037date:2020-05-04T00:00:00
db:VULMONid:CVE-2018-21159date:2020-05-04T00:00:00
db:JVNDBid:JVNDB-2018-016391date:2020-06-02T00:00:00
db:CNNVDid:CNNVD-202004-2208date:2020-05-06T00:00:00
db:NVDid:CVE-2018-21159date:2024-11-21T04:03:02.823

SOURCES RELEASE DATE

db:VULHUBid:VHN-132037date:2020-04-27T00:00:00
db:VULMONid:CVE-2018-21159date:2020-04-27T00:00:00
db:JVNDBid:JVNDB-2018-016391date:2020-06-02T00:00:00
db:CNNVDid:CNNVD-202004-2208date:2020-04-27T00:00:00
db:NVDid:CVE-2018-21159date:2020-04-27T18:15:12.607