Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-18862


Certain NETGEAR devices are affected by authentication bypass. This affects JGS516PE before 2017-05-11, JGS524Ev2 before 2017-05-11, JGS524PE before 2017-05-11, GS105Ev2 before 2017-05-11, GS105PE before 2017-05-11, GS108Ev3 before 2017-05-11, GS108PEv3 before 2017-05-11, GS116Ev2 before 2017-05-11, GSS108E before 2017-05-11, GSS116E before 2017-05-11, XS708Ev2 before 2017-05-11, and XS716E before 2017-05-11.


Published

2020-04-28T16:15:12.683

Last Modified

2024-11-21T03:21:07.230

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear jgs516pe_firmware < 2017-05-11 Yes
Hardware netgear jgs516pe - No
Operating System netgear jgs524e_firmware < 2017-05-11 Yes
Hardware netgear jgs524e v2 No
Operating System netgear jgs524pe_firmware < 2017-05-11 Yes
Hardware netgear jgs524pe - No
Operating System netgear gs105e_firmware < 2017-05-11 Yes
Hardware netgear gs105e v2 No
Operating System netgear gs105pe_firmware < 2017-05-11 Yes
Hardware netgear gs105pe - No
Operating System netgear gs108e_firmware < 2017-05-11 Yes
Hardware netgear gs108e v3 No
Operating System netgear gs108pe_firmware < 2017-05-11 Yes
Hardware netgear gs108pe v3 No
Operating System netgear gs116e_firmware < 2017-05-11 Yes
Hardware netgear gs116e v2 No
Operating System netgear gss108e_firmware < 2017-05-11 Yes
Hardware netgear gss108e - No
Operating System netgear gss116e_firmware < 2017-05-11 Yes
Hardware netgear gss116e - No
Operating System netgear xs708e_firmware < 2017-05-11 Yes
Hardware netgear xs708e v2 No
Operating System netgear xs716e_firmware < 2017-05-11 Yes
Hardware netgear xs716e - No

References