CVE-2021-37572

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Missing authorization).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mediatek:mt7603e_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mediatek:mt7613_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mediatek:mt7615_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mediatek:mt7622_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mediatek:mt7628_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mediatek:mt7629_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mediatek:mt7915_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*

History

06 Jan 2022, 17:48

Type Values Removed Values Added
References (MISC) https://kb.netgear.com/000064368/Security-Advisory-for-WiFi-WPS-and-IEEE-1905-Vulnerabilities-on-Multiple-Products-PSV-2021-0298-PSV-2021-0300 - (MISC) https://kb.netgear.com/000064368/Security-Advisory-for-WiFi-WPS-and-IEEE-1905-Vulnerabilities-on-Multiple-Products-PSV-2021-0298-PSV-2021-0300 - Third Party Advisory
References (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - Vendor Advisory
CPE cpe:2.3:o:mediatek:mt7915_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7615_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7603e_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7629_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7613_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7628_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7622_firmware:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*
First Time Mediatek mt7603e Firmware
Mediatek mt7613 Firmware
Mediatek mt7622
Mediatek mt7615 Firmware
Mediatek mt7613
Mediatek mt7629 Firmware
Mediatek mt7603e
Mediatek mt7915
Mediatek mt7622 Firmware
Mediatek mt7628
Mediatek mt7615
Mediatek
Mediatek mt7628 Firmware
Mediatek mt7629
Mediatek mt7915 Firmware
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

05 Jan 2022, 23:15

Type Values Removed Values Added
References
  • (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 -
Summary MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Missing authorization).

26 Dec 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-26 00:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-37572

Mitre link : CVE-2021-37572

CVE.ORG link : CVE-2021-37572


JSON object : View

Products Affected

mediatek

  • mt7628_firmware
  • mt7622_firmware
  • mt7628
  • mt7613
  • mt7615
  • mt7603e_firmware
  • mt7603e
  • mt7622
  • mt7629_firmware
  • mt7915_firmware
  • mt7629
  • mt7615_firmware
  • mt7613_firmware
  • mt7915
CWE
CWE-862

Missing Authorization