An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products. A specially crafted index value can cause an invalid memory read, resulting in a denial of service or remote information disclosure. An unauthenticated attacker can send a crafted packet on the local network to trigger this vulnerability.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0775 | Third Party Advisory |
http://www.securityfocus.com/bid/108820 | Broken Link |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
Information
Published : 2019-06-17 14:15
Updated : 2022-06-13 11:40
NVD link : CVE-2019-5016
Mitre link : CVE-2019-5016
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
kcodes
- netusb.ko
netgear
- r7900_firmware
- r8000
- r7900
- r8000_firmware