Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-14435


Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104, SRR60 before 2.5.2.104, SRK60B03 before 2.5.2.104, SRK60B04 before 2.5.2.104, SRK60B05 before 2.5.2.104, and SRK60B06 before 2.5.2.104.


Published

2020-06-18T17:15:12.640

Last Modified

2024-11-21T05:03:16.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear srk60_firmware < 2.5.2.104 Yes
Hardware netgear srk60 - No
Operating System netgear srs60_firmware < 2.5.2.104 Yes
Hardware netgear srs60 - No
Operating System netgear srr60_firmware < 2.5.2.104 Yes
Hardware netgear srr60 - No
Operating System netgear srk60b03_firmware < 2.5.2.104 Yes
Hardware netgear srk60b03 - No
Operating System netgear srk60b04_firmware < 2.5.2.104 Yes
Hardware netgear srk60b04 - No
Operating System netgear srk60b05_firmware < 2.5.2.104 Yes
Hardware netgear srk60b05 - No
Operating System netgear srk60b06_firmware < 2.5.2.104 Yes
Hardware netgear srk60b06 - No

References