CVE-2020-35782
Summary
| CVE | CVE-2020-35782 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-30 00:15:00 UTC |
| Updated | 2021-03-26 19:56:00 UTC |
| Description | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. The TFTP firmware update mechanism does not properly implement firmware validations, allowing remote attackers to write arbitrary data to internal memory. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Gs116e | v2 | All | All | All |
| Hardware | Netgear | Gs116e | v2 | All | All | All |
| Operating System | Netgear | Gs116e Firmware | All | All | All | All |
| Operating System | Netgear | Gs116e Firmware | All | All | All | All |
| Hardware | Netgear | Jgs516pe | - | All | All | All |
| Hardware | Netgear | Jgs516pe | - | All | All | All |
| Operating System | Netgear | Jgs516pe Firmware | All | All | All | All |
| Operating System | Netgear | Jgs516pe Firmware | All | All | All | All |
| Hardware | Netgear | Jgs524e | v2 | All | All | All |
| Hardware | Netgear | Jgs524e | v2 | All | All | All |
| Operating System | Netgear | Jgs524e Firmware | All | All | All | All |
| Operating System | Netgear | Jgs524e Firmware | All | All | All | All |
| Hardware | Netgear | Jgs524pe | - | All | All | All |
| Hardware | Netgear | Jgs524pe | - | All | All | All |
| Operating System | Netgear | Jgs524pe Firmware | All | All | All | All |
| Operating System | Netgear | Jgs524pe Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Technical Advisory – Multiple Vulnerabilities in Netgear ProSAFE Plus JGS516PE / GS116Ev2 Switches – NCC Group Research | MISC | research.nccgroup.com | |
| Security Advisory for Missing Function Level Access Control on Some Smart Managed Plus Switches, PSV-2020-0378 | Answer | NETGEAR Support | MISC | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.