CVE-2020-35801
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. A TFTP server was found to be active by default. It allows remote authenticated users to update the switch firmware.
Determinados dispositivos NETGEAR están afectados por una configuración incorrecta de los ajustes de seguridad. Esto afecta a JGS516PE versiones anteriores a 2.6.0.48, JGS524Ev2 versiones anteriores a 2.6.0.48, JGS524PE versiones anteriores a 2.6.0.48 y GS116Ev2 versiones anteriores a 2.6.0.48. Se encontró un servidor TFTP activo por defecto. Permite a los usuarios remotos autentificados actualizar el firmware del switch
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-29 CVE Reserved
- 2020-12-29 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Jgs516pe Firmware Search vendor "Netgear" for product "Jgs516pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs516pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs516pe Search vendor "Netgear" for product "Jgs516pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524e Firmware Search vendor "Netgear" for product "Jgs524e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524e Search vendor "Netgear" for product "Jgs524e" | v2 Search vendor "Netgear" for product "Jgs524e" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Jgs524pe Firmware Search vendor "Netgear" for product "Jgs524pe Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Jgs524pe Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Jgs524pe Search vendor "Netgear" for product "Jgs524pe" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Gs116e Firmware Search vendor "Netgear" for product "Gs116e Firmware" | < 2.6.0.48 Search vendor "Netgear" for product "Gs116e Firmware" and version " < 2.6.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Gs116e Search vendor "Netgear" for product "Gs116e" | v2 Search vendor "Netgear" for product "Gs116e" and version "v2" | - |
Safe
|