MEDIUM · 6.2

CVE-2022-21742

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt ...

Vulnerability Description

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.

CVSS Score

6.2

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
RealtekRtl8156 Firmware>= 7.42, <= 7.53
RealtekRtl8156-
RealtekRtl8156B Firmware>= 7.42, <= 7.53
RealtekRtl8156B-
RealtekRtl8153 Firmware>= 7.42, <= 7.53
RealtekRtl8153-
RealtekRtl8153B Firmware>= 7.42, <= 7.53
RealtekRtl8153B-
RealtekRtl8154 Firmware>= 7.42, <= 7.53
RealtekRtl8154-
RealtekRtl8154B Firmware>= 7.42, <= 7.53
RealtekRtl8154B-
RealtekRtl8152B Firmware>= 7.42, <= 7.53
RealtekRtl8152B-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-21742?

CVE-2022-21742 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt ...

How severe is CVE-2022-21742?

CVE-2022-21742 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-21742?

Check the references section above for vendor advisories and patch information. Affected products include: Realtek Rtl8156 Firmware, Realtek Rtl8156, Realtek Rtl8156B Firmware, Realtek Rtl8156B, Realtek Rtl8153 Firmware.