PT-2013-5182 · NetGear · Prosafe Gs728Tps+6
Published
2013-12-19
·
Updated
2013-12-19
·
CVE-2013-4775
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR ProSafe GS724Tv3 versions 5.4.1.13 and earlier
NETGEAR ProSafe GS716Tv2 versions 5.4.1.13 and earlier
NETGEAR ProSafe GS748Tv4 version 5.4.1.14
NETGEAR ProSafe GS510TP version 5.4.0.6
NETGEAR ProSafe GS752TPS version 5.3.0.17
NETGEAR ProSafe GS728TPS version 5.3.0.17
NETGEAR ProSafe GS728TS version 5.3.0.17
NETGEAR ProSafe GS725TS version 5.3.0.17
NETGEAR ProSafe GS752TXS version 6.1.0.12
NETGEAR ProSafe GS728TXS version 6.1.0.12
Description
The issue allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to the filesystem/startup-config.
Recommendations
For NETGEAR ProSafe GS724Tv3 versions 5.4.1.13 and earlier, update to a version later than 5.4.1.13.
For NETGEAR ProSafe GS716Tv2 versions 5.4.1.13 and earlier, update to a version later than 5.4.1.13.
For NETGEAR ProSafe GS748Tv4 version 5.4.1.14, update to a version later than 5.4.1.14.
For NETGEAR ProSafe GS510TP version 5.4.0.6, update to a version later than 5.4.0.6.
For NETGEAR ProSafe GS752TPS version 5.3.0.17, update to a version later than 5.3.0.17.
For NETGEAR ProSafe GS728TPS version 5.3.0.17, update to a version later than 5.3.0.17.
For NETGEAR ProSafe GS728TS version 5.3.0.17, update to a version later than 5.3.0.17.
For NETGEAR ProSafe GS725TS version 5.3.0.17, update to a version later than 5.3.0.17.
For NETGEAR ProSafe GS752TXS version 6.1.0.12, update to a version later than 6.1.0.12.
For NETGEAR ProSafe GS728TXS version 6.1.0.12, update to a version later than 6.1.0.12.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosafe Gs510Tp
Prosafe Gs716Tv2
Prosafe Gs724Tv3
Prosafe Gs725Ts
Prosafe Gs728Tps
Prosafe Gs748Tv4
Prosafe Gs752Tps