Cross-Site Request Forgery Vulnerability in NETGEAR ReadyNAS Devices
CVE-2018-21102

8.8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
23 April 2020

Summary

NETGEAR ReadyNAS devices prior to version 6.9.3 are susceptible to Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to bypass security controls by tricking a user into executing unwanted actions without their consent. Such exploitation can compromise the integrity and confidentiality of sensitive data managed by the ReadyNAS system. Users are advised to apply the latest updates to mitigate the risks associated with this security issue.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.