SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-20699

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker.

CRITICAL 9.8EPSS 1.14%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS408EPP before 1.0.0.15, GS808E before 1.7.0.7, GS908E before 1.7.0.3, GSS108E before 1.6.0.4, and GSS108EPP before 1.0.0.15.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
netgear/gs105e firmware · netgear/gs105pe firmware · netgear/gs408epp firmware · netgear/gs808e firmware · netgear/gs908e firmware · netgear/gss108e firmware · netgear/gss108epp firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.