VulnerabilityModified
CVE-2020-13245
Certain NETGEAR devices are affected by Missing SSL Certificate Validation.
MEDIUM 5.9EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- netgear/r6120 firmware · netgear/r6220 firmware · netgear/r6350 firmware · netgear/r6400 firmware · netgear/r6800 firmware · netgear/r6850 firmware · netgear/r7000p firmware · netgear/r7800 firmware · netgear/r8000 firmware · netgear/r9000 firmware · netgear/rax120 firmware · netgear/rbr20 firmware · netgear/xr300 firmware · netgear/xr500 firmware
- Source
- cve@mitre.org
References
- https://iot-lab-fh-ooe.github.io/netgear_update_vulnerability/Exploit, Third Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
- https://iot-lab-fh-ooe.github.io/netgear_update_vulnerability/Exploit, Third Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.