// For flags

CVE-2014-2969

 

Severity Score

8.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware or read or modify memory contents, and consequently execute arbitrary code, via a request to (1) produce_burn.cgi, (2) register_debug.cgi, or (3) bootcode_update.cgi.

Switches NETGEAR GS108PE Prosafe Plus con firmware 1.2.0.5 tienen una contraseña embebida de debugpassword para la cuenta ntgruser, lo que permite a atacantes remotos subir firmware o leer o modificar los contenidos de la memoria, y como consecuencia ejecutar código arbitrario, a través de una solicitud en (1) produce_burn.cgi, (2) register_debug.cgi, o (3) bootcode_update.cgi.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-04-21 CVE Reserved
  • 2014-07-07 CVE Published
  • 2023-04-27 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
References (1)
URL Tag Source
http://www.kb.cert.org/vuls/id/143740 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netgear
Search vendor "Netgear"
Gs108pe Firmware
Search vendor "Netgear" for product "Gs108pe Firmware"
1.2.0.5
Search vendor "Netgear" for product "Gs108pe Firmware" and version "1.2.0.5"
-
Affected
in Netgear
Search vendor "Netgear"
Gs108pe
Search vendor "Netgear" for product "Gs108pe"
--
Affected