CVE-2020-35782
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory.
Determinados dispositivos NETGEAR están afectados por una falta de control de acceso en el nivel de función. Esto afecta a JGS516PE versiones anteriores a 2.6.0.48, JGS524Ev2 versiones anteriores a 2.6.0.48, JGS524PE versiones anteriores a 2.6.0.48 y GS116Ev2 versiones anteriores a 2.6.0.48. El mecanismo de actualización del firmware TFTP no implementa correctamente las validaciones del firmware, lo que permite a los atacantes remotos escribir datos arbitrarios en la memoria interna
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-29 CVE Reserved
- 2020-12-29 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Jgs516pe Firmware Search vendor "Netgear" for product "Jgs516pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs516pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs516pe Search vendor "Netgear" for product "Jgs516pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524e Firmware Search vendor "Netgear" for product "Jgs524e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524e Search vendor "Netgear" for product "Jgs524e" | v2 Search vendor "Netgear" for product "Jgs524e" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524pe Firmware Search vendor "Netgear" for product "Jgs524pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524pe Search vendor "Netgear" for product "Jgs524pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Gs116e Firmware Search vendor "Netgear" for product "Gs116e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Gs116e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Gs116e Search vendor "Netgear" for product "Gs116e" | v2 Search vendor "Netgear" for product "Gs116e" and version "v2" | - |
Safe
|