Netgear Prosafe Network Management System vulnerabilities
25 known vulnerabilities affecting netgear/prosafe_network_management_system.
Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21
Vulnerabilities
Page 2 of 2
CVE-2023-38102P2HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38102 [HIGH] CWE-862 CVE-2023-38102: NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vuln
NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism
nvd
CVE-2023-49693P2CRITICALCVSS 9.8fixed in 1.7.0.342023-11-29
CVE-2023-49693 [CRITICAL] CWE-306 CVE-2023-49693: NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 116
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
nvd
CVE-2023-38100P3HIGHCVSS 8.8fixed in 1.7.0.20v1.7.0.12 (Win64)2024-05-03
CVE-2023-38100 [HIGH] CWE-89 CVE-2023-38100: NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnera
NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can
nvd
CVE-2024-5245P3HIGHCVSS 7.8fixed in 1.7.0.37v1.7.0.34 x642024-05-23
CVE-2024-5245 [HIGH] CWE-1392 CVE-2024-5245: NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerabili
NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit
nvd
CVE-2023-49694P3HIGHCVSS 7.8fixed in 1.7.0.312023-11-29
CVE-2023-49694 [HIGH] CWE-284 CVE-2023-49694: A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management S
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.
nvd
← Previous2 / 2