Back to overview

CVE-2019-5016

CRITICAL
10.0
CVSS 3.0
Description
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products. A specially crafted index value can cause an invalid memory read, resulting in a denial of service or remote information disclosure. An unauthenticated attacker can send a crafted packet on the local network to trigger this vulnerability.

Metadata

CVE ID
CVE-2019-5016
State
PUBLISHED
Assigner
talos
Reserved
2019-01-04 00:00 UTC
Published
2019-06-17 20:29 UTC
Last updated
2024-08-04 19:40 UTC
Primary CWE
CWE-200
CWE-200: Information Exposure
Vendor / Product
Talos / KCodes
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
Talos KCodes NETGEAR Nighthawk AC3200 (R8000) Firmware Version V1.0.4.2810.1.54 (11/7/18) - NetUSB.ko 1.0.2.66, NETGEAR Nighthawk AC3000 (R7900) Firmware Version V1.0.3.810.0.37 (11/1/18) - NetUSB.ko 1.0.2.69
Weakness (CWE)
CWESourceDescription
CWE-200 cna CWE-200: Information Exposure
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Back to overview