CVE-2014-4864
Netgear GS105Ev2 Authentication Bypass / XSS / CSRF
Severity Score
3.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.
La utilidad de configuración NETGEAR ProSafe Plus crea ficheros de la copia de seguridad de la configuración que contienen las contraseñas en texto plano, lo que podría permitir a los atacantes remotos obtener información sensible mediante la lectura de un fichero.
The Netgear GS105Ev2 gigabit switch suffers from authentication bypass, cross site request forgery, cross site scripting, and various other vulnerabilities.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-07-10 CVE Reserved
- 2014-09-10 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/396212 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Prosafe Firmware Search vendor "Netgear" for product "Prosafe Firmware" | <= 6.1.0.12 Search vendor "Netgear" for product "Prosafe Firmware" and version " <= 6.1.0.12" | - |
Affected
|