2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-27644" ,
"sourceIdentifier" : "zdi-disclosures@trendmicro.com" ,
"published" : "2023-03-29T19:15:08.563" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T06:56:05.187" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15797."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV30" : [
{
"source" : "zdi-disclosures@trendmicro.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.0 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 3.4
}
]
} ,
"weaknesses" : [
{
"source" : "zdi-disclosures@trendmicro.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-295"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.4.126" ,
"matchCriteriaId" : "AFC79CFE-9036-472C-AB28-FF293BBE1780"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52AE9AD2-BC8D-477D-A3D3-891AE52FA5F3"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.4.126" ,
"matchCriteriaId" : "169E2D0D-7D18-4AF1-8683-346BD1069DC1"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A09A9E8-8C77-4EDB-9483-B3C540EF083A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.3.3.148" ,
"matchCriteriaId" : "E52E9373-C896-405F-9CEC-2E8707B249F5"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r6900p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C41908FF-AE64-4949-80E3-BEE061B2DA8A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.11.134" ,
"matchCriteriaId" : "5376DD03-0DDD-4B0C-A185-EC226515B32A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9F86FF6-AB32-4E51-856A-DDE790C0A9A6"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.3.3.148" ,
"matchCriteriaId" : "5D67D8C3-98DA-4B7D-BA7D-AB5F13E627F9"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DFE55F4D-E98B-46D3-B870-041141934CD1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.5.84" ,
"matchCriteriaId" : "8EA99A24-E836-40F4-BF61-C4489E3713F0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r7850:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DAF94D73-B6D0-4334-9A41-83AA92B7C6DF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.4.3.88" ,
"matchCriteriaId" : "150CF98F-A933-4CF2-A4FF-5AF15A9E1E18"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r7960p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "091CEDB5-0069-4253-86D8-B9FE17CB9F24"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.4.84" ,
"matchCriteriaId" : "72325BC2-C9AC-4B24-865E-662BDF05BD99"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r8000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B39F095-8FE8-43FD-A866-7B613B495984"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.4.3.88" ,
"matchCriteriaId" : "994D00CD-350B-4059-9C51-BF843C72B45E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:r8000p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F7EF872D-2537-4FEB-8799-499FC9D44339"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.6.138" ,
"matchCriteriaId" : "C706F152-6163-4276-B608-C4AF196E070F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rax200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "58EB0F2F-FB5C-47D9-9AE6-087AE517B3F9"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.6.138" ,
"matchCriteriaId" : "E301ACAC-E217-4329-8A32-83946E61999E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rax75:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1BAA74D7-36A1-4494-96A2-BD0D2D6BF22F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.0.6.138" ,
"matchCriteriaId" : "F8028906-D5AB-4CE6-8431-844E6F98B9AD"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "06B5A85C-3588-4263-B9AD-4E56D3F6CB16"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rs400_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "1.5.1.86" ,
"matchCriteriaId" : "3BC7E8C9-62BD-45E2-8A7A-D29A6150622A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rs400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2700644E-0940-4D05-B3CA-904D91739E58"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.5.0.28" ,
"matchCriteriaId" : "9C1671BC-AB3B-493F-81F6-C38D1489BF9C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:cbr40:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE0F7E9E-196C-4106-B1C9-C16FA5910A0F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:lbr1020_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.2" ,
"matchCriteriaId" : "03942539-865D-4920-8C59-D211C6A5E97C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:lbr1020:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "953F0743-4B34-4CE9-815E-D87253720CBE"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:lbr20_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.2" ,
"matchCriteriaId" : "22C90106-692A-4574-907A-86B7BA743AEF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:lbr20:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "863E45EA-2DA0-4C9A-9B87-79E42B3FF97C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbr10_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "6AC9F546-DE9F-4B4F-B6C0-166A109FC4F6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbr10:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5DADAA79-9A5C-4B6F-A58D-704ACD1C3334"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbr20_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "0583B690-ABA5-4E18-AE1F-2ADA800B2AF3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbr20:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE5DBD66-9C2A-4EFF-87AB-03E791D584B5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbr40_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "008227D9-B549-48EB-BEE5-492461CD3654"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbr40:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A9E20E59-2B1E-4E43-A494-2C20FD716D4F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbr50_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "0789B88D-574A-4FF7-A579-6FD0DF5CCA1F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbr50:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B2CAEA32-6934-4743-9E6B-22D52AC5E7F8"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbs10_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "C119E51F-AC11-48F9-85AA-29255E64F8DC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbs10:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32BAB5C0-F645-4A90-833F-6345335FA1AF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbs20_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "35792D02-E5E4-41D1-9AB8-C595015A6608"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbs20:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "14FC7F5B-7E4F-4A68-8427-D1F553EBE8CA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbs40_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "8ED42A4B-C04A-431D-8CE5-F219BFC1FA39"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbs40:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6FDCDE39-0355-43B9-BF57-F3718DA2988D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netgear:rbs50_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.7.4.24" ,
"matchCriteriaId" : "26315AA3-35C7-415F-B12E-D0081DCA5A52"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netgear:rbs50:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3BCFD959-D522-4FA0-AD01-2937DAEE1EDF"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://kb.netgear.com/000064721/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0324" ,
"source" : "zdi-disclosures@trendmicro.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://www.zerodayinitiative.com/advisories/ZDI-22-520/" ,
"source" : "zdi-disclosures@trendmicro.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://kb.netgear.com/000064721/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0324" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://www.zerodayinitiative.com/advisories/ZDI-22-520/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
}
]
}