MEDIUM
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi
Published Nov 5, 2024
5.7
MEDIUMCVSS 3.1
EPSS 0.30%
Description
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Affected products
No data.
Configuration 1
AND
- 1.0.2.160
Configuration 2
AND
- 1.0.3.78
Configuration 3
AND
- 1.3.3.154
Configuration 4
AND
- 1.0.4.128
-
- Version 1.0.4.128StatusaffectedConstraints-
- Version
-
- Version 1.3.3.154StatusaffectedConstraints-
- Version
-
- Version 1.0.2.160StatusaffectedConstraints-
- Version
-
- Version 1.0.3.78StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NETGEAR | R6400 Firmware | n/a |
| ||||||
| NETGEAR | R7000p Firmware | n/a |
| ||||||
| NETGEAR | R8500 Firmware | n/a |
| ||||||
| NETGEAR | Xr300 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_43/43.md Broken Link
- https://www.netgear.com/about/security/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_43/43.md | Broken Link | |
| https://www.netgear.com/about/security/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 5, 2024
Updated Nov 5, 2024
Reserved Nov 4, 2024
Link CVE-2024-52014
CISA Vulnrichment
Updated Nov 5, 2024