CVE-2017-18715
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
24/04/2020
Last modified:
28/04/2020
Description
Certain NETGEAR devices are affected by reflected XSS. This affects EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:netgear:ex3700_firmware:*:*:*:*:*:*:*:* | 1.0.0.66 (excluding) | |
cpe:2.3:h:netgear:ex3700:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex3800_firmware:*:*:*:*:*:*:*:* | 1.0.0.66 (excluding) | |
cpe:2.3:h:netgear:ex3800:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6100_firmware:*:*:*:*:*:*:*:* | 1.0.2.20 (excluding) | |
cpe:2.3:h:netgear:ex6100:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6120_firmware:*:*:*:*:*:*:*:* | 1.0.0.34 (excluding) | |
cpe:2.3:h:netgear:ex6120:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6150_firmware:*:*:*:*:*:*:*:* | 1.0.0.36 (excluding) | |
cpe:2.3:h:netgear:ex6150:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:* | 1.0.3.84 (excluding) | |
cpe:2.3:h:netgear:ex6200:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:netgear:ex7000_firmware:*:*:*:*:*:*:*:* | 1.0.0.60 (excluding) | |
cpe:2.3:h:netgear:ex7000:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page