← Back

CVE-2019-5016

nvd nist
Published: Jun 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products. A specially crafted index value can cause an invalid memory read, resulting in a denial of service or remote information disclosure. An unauthenticated attacker can send a crafted packet on the local network to trigger this vulnerability.

Affected (4)

2 products
R8000 Firmware
R7900 Firmware
1 product
Netusb.ko
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.28_10.1.54
Running on/withPlatform Versions
Netgear
R8000
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.3.810.037
Running on/withPlatform Versions
Netgear
R7900
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Kcodes
Version 1.0.2.66
Version 1.0.2.69

References (4)

Source: talos-cna@cisco.com
Broken Link
Source: talos-cna@cisco.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.