Netgear Prosafe Network Management System vulnerabilities

25 known vulnerabilities affecting netgear/prosafe_network_management_system.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21

Vulnerabilities

Page 1 of 2
CVE-2024-6814HIGHCVSS 8.8v1.7.0.34v1.7.0.34 x642024-08-21
CVE-2024-6814 [HIGH] CWE-89 CVE-2024-6814: NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulner NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getFilterSt
cvelistv5nvd
CVE-2024-6813HIGHCVSS 8.8v1.7.0.34v1.7.0.34 x642024-08-21
CVE-2024-6813 [HIGH] CWE-89 CVE-2024-6813: NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerab NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getSortString
cvelistv5nvd
CVE-2024-5505HIGHCVSS 8.8fixed in 1.7.0.37v1.7.0.34 x642024-06-06
CVE-2024-5505 [HIGH] CWE-22 CVE-2024-5505: NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vu NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the UpLoadS
cvelistv5nvd
CVE-2024-5247HIGHCVSS 8.8fixed in 1.7.0.37v1.7.0.34 x642024-05-23
CVE-2024-5247 [HIGH] CWE-434 CVE-2024-5247: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Executi NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the U
cvelistv5nvd
CVE-2024-5246HIGHCVSS 8.8v1.7.0.34 x642024-05-23
CVE-2024-5246 [HIGH] CWE-1395 CVE-2024-5246: NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerabi NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the product installer. The issue res
cvelistv5nvd
CVE-2024-5245HIGHCVSS 7.8fixed in 1.7.0.37v1.7.0.34 x642024-05-23
CVE-2024-5245 [HIGH] CWE-1392 CVE-2024-5245: NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerabili NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit
cvelistv5nvd
CVE-2023-38096CRITICALCVSS 9.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38096 [CRITICAL] CWE-287 CVE-2023-38096: NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerIn
cvelistv5nvd
CVE-2023-50231CRITICALCVSS 9.6fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-50231 [CRITICAL] CWE-79 CVE-2023-50231: NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vu NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists withi
cvelistv5nvd
CVE-2023-44449HIGHCVSS 8.8fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-44449 [HIGH] CWE-89 CVE-2023-44449: NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnera NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the clearAlertByI
cvelistv5nvd
CVE-2023-38097HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38097 [HIGH] CWE-749 CVE-2023-38097: NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code E NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authenti
cvelistv5nvd
CVE-2023-44450HIGHCVSS 8.8fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-44450 [HIGH] CWE-89 CVE-2023-44450: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Exec NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within t
cvelistv5nvd
CVE-2023-38102HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38102 [HIGH] CWE-862 CVE-2023-38102: NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vuln NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism
cvelistv5nvd
CVE-2023-38095HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38095 [HIGH] CWE-434 CVE-2023-38095: NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authen
cvelistv5nvd
CVE-2023-38101HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38101 [HIGH] CWE-749 CVE-2023-38101: NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing aut
cvelistv5nvd
CVE-2023-38099HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38099 [HIGH] CWE-89 CVE-2023-38099: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Exec NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authenticati
cvelistv5nvd
CVE-2023-38100HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38100 [HIGH] CWE-89 CVE-2023-38100: NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnera NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can
cvelistv5nvd
CVE-2023-41182HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-41182 [HIGH] CWE-22 CVE-2023-41182: NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnera NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism
cvelistv5nvd
CVE-2023-38098HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38098 [HIGH] CWE-434 CVE-2023-38098: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Executi NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication
cvelistv5nvd
CVE-2023-49693CRITICALCVSS 9.8fixed in 1.7.0.342023-11-29
CVE-2023-49693 [CRITICAL] CWE-306 CVE-2023-49693: NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 116 NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
nvd
CVE-2023-49694HIGHCVSS 7.8fixed in 1.7.0.312023-11-29
CVE-2023-49694 [HIGH] CWE-284 CVE-2023-49694: A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management S A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.
nvd