cbcvebase.

Netgear Prosafe Network Management System vulnerabilities

25 known vulnerabilities affecting netgear/prosafe_network_management_system.

Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21

Vulnerabilities

Page 1 of 2
CVE-2023-38096P1CRITICALCVSS 9.8PoCfixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38096 [CRITICAL] CWE-287 CVE-2023-38096: NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerIn
nvd
CVE-2023-38098P2HIGHCVSS 8.8PoCfixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38098 [HIGH] CWE-434 CVE-2023-38098: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Executi NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication
nvd
CVE-2023-38095P1HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38095 [HIGH] CWE-434 CVE-2023-38095: NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authen
nvd
CVE-2023-41182P1HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-41182 [HIGH] CWE-22 CVE-2023-41182: NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnera NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism
nvd
CVE-2021-27273P2HIGHCVSS 8.8v1.6.0.262021-03-29
CVE-2021-27273 [HIGH] CWE-78 CVE-2021-27273: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NE This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the SettingConfigController class. When parsing th
nvd
CVE-2023-38099P2HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38099 [HIGH] CWE-89 CVE-2023-38099: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Exec NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authenticati
nvd
CVE-2023-44450P2HIGHCVSS 8.8fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-44450 [HIGH] CWE-89 CVE-2023-44450: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Exec NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within t
nvd
CVE-2024-5505P1HIGHCVSS 8.8fixed in 1.7.0.37v1.7.0.34 x642024-06-06
CVE-2024-5505 [HIGH] CWE-22 CVE-2024-5505: NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vu NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the UpLoadS
nvd
CVE-2021-27275P2HIGHCVSS 8.3v1.6.0.262021-03-29
CVE-2021-27275 [HIGH] CWE-22 CVE-2021-27275: This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary fi This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ConfigFileC
nvd
CVE-2023-44449P2HIGHCVSS 8.8fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-44449 [HIGH] CWE-89 CVE-2023-44449: NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnera NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the clearAlertByI
nvd
CVE-2024-5247P2HIGHCVSS 8.8fixed in 1.7.0.37v1.7.0.34 x642024-05-23
CVE-2024-5247 [HIGH] CWE-434 CVE-2024-5247: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Executi NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the U
nvd
CVE-2024-5246P2HIGHCVSS 8.8v1.7.0.34 x642024-05-23
CVE-2024-5246 [HIGH] CWE-1395 CVE-2024-5246: NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerabi NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the product installer. The issue res
nvd
CVE-2021-27272P2HIGHCVSS 7.1v1.6.0.262021-03-29
CVE-2021-27272 [HIGH] CWE-22 CVE-2021-27272: This vulnerability allows remote attackers to delete arbitrary files on affected installations of NE This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing t
nvd
CVE-2021-27276P2HIGHCVSS 7.1v1.6.0.262021-03-29
CVE-2021-27276 [HIGH] CWE-22 CVE-2021-27276: This vulnerability allows remote attackers to delete arbitrary files on affected installations of NE This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName
nvd
CVE-2023-50231P2CRITICALCVSS 9.6fixed in 1.7.0.31v1.7.0.26 x642024-05-03
CVE-2023-50231 [CRITICAL] CWE-79 CVE-2023-50231: NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vu NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists withi
nvd
CVE-2021-27274P2CRITICALCVSS 9.8v1.6.0.262021-03-29
CVE-2021-27274 [CRITICAL] CWE-434 CVE-2021-27274: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NE This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper validation of a user-supplied
nvd
CVE-2023-38101P2HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38101 [HIGH] CWE-749 CVE-2023-38101: NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing aut
nvd
CVE-2023-38097P2HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38097 [HIGH] CWE-749 CVE-2023-38097: NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code E NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authenti
nvd
CVE-2024-6813P2HIGHCVSS 8.8v1.7.0.34v1.7.0.34 x642024-08-21
CVE-2024-6813 [HIGH] CWE-89 CVE-2024-6813: NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerab NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getSortString
nvd
CVE-2024-6814P2HIGHCVSS 8.8v1.7.0.34v1.7.0.34 x642024-08-21
CVE-2024-6814 [HIGH] CWE-89 CVE-2024-6814: NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulner NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getFilterSt
nvd
Netgear Prosafe Network Management System vulnerabilities | cvebase