CVE-2021-45511

CVSS V2 High 10 CVSS V3 Critical 9.8
Description
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 before 2021-08-27, R6330 before 2021-08-27, R6350 before 2021-08-27, R6700v2 before 2021-08-27, R6800 before 2021-08-27, R6850 before 2021-08-27, R6900v2 before 2021-08-27, R7200 before 2021-08-27, R7350 before 2021-08-27, R7400 before 2021-08-27, and R7450 before 2021-08-27.
Overview
  • CVE ID
  • CVE-2021-45511
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2021-12-26T01:15:13
  • Last Modified Date
  • 2022-07-12T17:42:04
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:netgear:ac2100_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:ac2100:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:ac2400_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:ac2400:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:ac2600_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:ac2600:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:d7000_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.1.80
cpe:2.3:h:netgear:d7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.110
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6230_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.110
cpe:2.3:h:netgear:r6230:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6260_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.84
cpe:2.3:h:netgear:r6260:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6330_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.84
cpe:2.3:h:netgear:r6330:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6350_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.84
cpe:2.3:h:netgear:r6350:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6700v2_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r6700v2:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6800_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r6800:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6850_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.84
cpe:2.3:h:netgear:r6850:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6900v2_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r6900v2:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7200_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r7200:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7350_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r7350:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7400_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r7400:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7450_firmware:*:*:*:*:*:*:*:* 1 OR 1.2.0.88
cpe:2.3:h:netgear:r7450:-:*:*:*:*:*:*:* 0 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 10
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 10
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
History
Created Old Value New Value Data Type Notes
2022-05-10 06:38:10 Added to TrackCVE
2022-12-06 04:53:41 2021-12-26T01:15Z 2021-12-26T01:15:13 CVE Published Date updated
2022-12-06 04:53:41 2022-07-12T17:42:04 CVE Modified Date updated
2022-12-06 04:53:41 Analyzed Vulnerability Status updated