ID

VAR-202010-0588


CVE

CVE-2020-26922


TITLE

plural  NETGEAR  Command injection vulnerabilities in the product

Trust: 0.8

sources: JVNDB: JVNDB-2020-012118

DESCRIPTION

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24. plural NETGEAR The product contains a command injection vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-26922 // JVNDB: JVNDB-2020-012118

AFFECTED PRODUCTS

vendor:netgearmodel:wc7600v2scope:ltversion:6.5.5.24

Trust: 1.0

vendor:netgearmodel:wc7500scope:ltversion:6.5.5.24

Trust: 1.0

vendor:netgearmodel:wc9500scope:ltversion:6.5.5.24

Trust: 1.0

vendor:netgearmodel:wc7600scope:ltversion:6.5.5.24

Trust: 1.0

vendor:ネットギアmodel:wc7500scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:wc7600v2scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:wc7600scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:wc9500scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-012118 // NVD: CVE-2020-26922

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-26922
value: MEDIUM

Trust: 1.0

cve@mitre.org: CVE-2020-26922
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-26922
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202010-354
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-26922
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-26922
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

cve@mitre.org: CVE-2020-26922
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-26922
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-012118 // CNNVD: CNNVD-202010-354 // NVD: CVE-2020-26922 // NVD: CVE-2020-26922

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:Command injection (CWE-77) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-012118 // NVD: CVE-2020-26922

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202010-354

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-202010-354

PATCH

title:Security Advisory for Post-Authentication Command Injection on Some Wireless Controllers, PSV-2020-0139url:https://kb.netgear.com/000062330/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Wireless-Controllers-PSV-2020-0139

Trust: 0.8

title:Multiple NETGEAR Fixes for device command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131140

Trust: 0.6

sources: JVNDB: JVNDB-2020-012118 // CNNVD: CNNVD-202010-354

EXTERNAL IDS

db:NVDid:CVE-2020-26922

Trust: 2.4

db:JVNDBid:JVNDB-2020-012118

Trust: 0.8

db:CNNVDid:CNNVD-202010-354

Trust: 0.6

sources: JVNDB: JVNDB-2020-012118 // CNNVD: CNNVD-202010-354 // NVD: CVE-2020-26922

REFERENCES

url:https://kb.netgear.com/000062330/security-advisory-for-post-authentication-command-injection-on-some-wireless-controllers-psv-2020-0139

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-26922

Trust: 1.4

sources: JVNDB: JVNDB-2020-012118 // CNNVD: CNNVD-202010-354 // NVD: CVE-2020-26922

SOURCES

db:JVNDBid:JVNDB-2020-012118
db:CNNVDid:CNNVD-202010-354
db:NVDid:CVE-2020-26922

LAST UPDATE DATE

2024-11-23T21:35:14.200000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-012118date:2021-04-26T03:13:00
db:CNNVDid:CNNVD-202010-354date:2020-10-21T00:00:00
db:NVDid:CVE-2020-26922date:2024-11-21T05:20:30.220

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-012118date:2021-04-26T00:00:00
db:CNNVDid:CNNVD-202010-354date:2020-10-09T00:00:00
db:NVDid:CVE-2020-26922date:2020-10-09T07:15:17.857