CVE-2020-35783
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48. The NSDP protocol version allows unauthenticated remote attackers to obtain all the switch configuration parameters by sending the corresponding read requests.
Determinados dispositivos NETGEAR están afectados por una falta de control de acceso en el nivel de función. Esto afecta a JGS516PE versiones anteriores a 2.6.0.48, GS116Ev2 versiones anteriores a 2.6.0.48, JGS524Ev2 versiones anteriores a 2.6.0.48 y JGS524PE versiones anteriores a 2.6.0.48. La versión del protocolo NSDP permite a los atacantes remotos no autentificados obtener todos los parámetros de configuración del switch enviando las correspondientes peticiones de lectura.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-29 CVE Reserved
- 2020-12-29 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Jgs516pe Firmware Search vendor "Netgear" for product "Jgs516pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs516pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs516pe Search vendor "Netgear" for product "Jgs516pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524e Firmware Search vendor "Netgear" for product "Jgs524e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524e Search vendor "Netgear" for product "Jgs524e" | v2 Search vendor "Netgear" for product "Jgs524e" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524pe Firmware Search vendor "Netgear" for product "Jgs524pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524pe Search vendor "Netgear" for product "Jgs524pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Gs116e Firmware Search vendor "Netgear" for product "Gs116e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Gs116e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Gs116e Search vendor "Netgear" for product "Gs116e" | v2 Search vendor "Netgear" for product "Gs116e" and version "v2" | - |
Safe
|