HIGH · 7.6

CVE-2021-45493

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

Vulnerability Description

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

CVSS Score

7.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
NetgearRax35 Firmware< 1.0.4.102
NetgearRax35-
NetgearRax38 Firmware< 1.0.4.102
NetgearRax38-
NetgearRax40 Firmware< 1.0.4.102
NetgearRax40-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-45493?

CVE-2021-45493 is a vulnerability with a CVSS score of 7.6 (HIGH). Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

How severe is CVE-2021-45493?

CVE-2021-45493 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-45493?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Rax35 Firmware, Netgear Rax35, Netgear Rax38 Firmware, Netgear Rax38, Netgear Rax40 Firmware.