CVE-2017-18789

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6250 before V1.0.4.8, R6400 before V1.0.1.22, R6400v2 before V1.0.2.32, R7100LG before V1.0.0.32, R7300 before V1.0.0.52, R8300 before V1.0.2.94, R8500 before V1.0.2.100, D6220 before V1.0.0.28, D6400 before V1.0.0.60, and D8500 before V1.0.3.29.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AC:L/AV:L/A:N/C:H/I:N/PR:N/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
netgearr6250_firmware
𝑥
< 1.0.4.8
netgearr6400_firmware
𝑥
< 1.0.1.22
netgearr6400_firmware
𝑥
< 1.0.2.32
netgearr7100lg_firmware
𝑥
< 1.0.0.32
netgearr7300_firmware
𝑥
< 1.0.0.52
netgearr8300_firmware
𝑥
< 1.0.2.94
netgearr8500_firmware
𝑥
< 1.0.2.100
netgeard6220_firmware
𝑥
< 1.0.0.28
netgeard6400_firmware
𝑥
< 1.0.0.60
netgeard8500_firmware
𝑥
< 1.0.3.29
𝑥
= Vulnerable software versions