CVE-2020-35783
Summary
| CVE | CVE-2020-35783 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-30 00:15:00 UTC |
| Updated | 2021-03-23 17:16:00 UTC |
| Description | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48. The NSDP protocol version allows unauthenticated remote attackers to obtain all the switch configuration parameters by sending the corresponding read requests. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Gs116e | v2 | All | All | All |
| Hardware | Netgear | Gs116e | v2 | All | All | All |
| Operating System | Netgear | Gs116e Firmware | All | All | All | All |
| Operating System | Netgear | Gs116e Firmware | All | All | All | All |
| Hardware | Netgear | Jgs516pe | - | All | All | All |
| Hardware | Netgear | Jgs516pe | - | All | All | All |
| Operating System | Netgear | Jgs516pe Firmware | All | All | All | All |
| Operating System | Netgear | Jgs516pe Firmware | All | All | All | All |
| Hardware | Netgear | Jgs524e | v2 | All | All | All |
| Hardware | Netgear | Jgs524e | v2 | All | All | All |
| Operating System | Netgear | Jgs524e Firmware | All | All | All | All |
| Operating System | Netgear | Jgs524e Firmware | All | All | All | All |
| Hardware | Netgear | Jgs524pe | - | All | All | All |
| Hardware | Netgear | Jgs524pe | - | All | All | All |
| Operating System | Netgear | Jgs524pe Firmware | All | All | All | All |
| Operating System | Netgear | Jgs524pe Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Technical Advisory – Multiple Vulnerabilities in Netgear ProSAFE Plus JGS516PE / GS116Ev2 Switches – NCC Group Research | MISC | research.nccgroup.com | |
| Security Advisory for Missing Function Level Access Control on Some Smart Managed Plus Switches, PSV-2020-0383 | Answer | NETGEAR Support | MISC | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.