PT-2020-8409 · NetGear · Gs105Pe+10

Published

2020-04-28

·

Updated

2020-05-05

·

CVE-2017-18862

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NETGEAR JGS516PE versions prior to 2017-05-11 NETGEAR JGS524Ev2 versions prior to 2017-05-11 NETGEAR JGS524PE versions prior to 2017-05-11 NETGEAR GS105Ev2 versions prior to 2017-05-11 NETGEAR GS105PE versions prior to 2017-05-11 NETGEAR GS108Ev3 versions prior to 2017-05-11 NETGEAR GS108PEv3 versions prior to 2017-05-11 NETGEAR GS116Ev2 versions prior to 2017-05-11 NETGEAR GSS108E versions prior to 2017-05-11 NETGEAR GSS116E versions prior to 2017-05-11 NETGEAR XS708Ev2 versions prior to 2017-05-11 NETGEAR XS716E versions prior to 2017-05-11
Description: The issue is related to authentication bypass in certain NETGEAR devices.
Recommendations: For JGS516PE, update to a version released after 2017-05-11. For JGS524Ev2, update to a version released after 2017-05-11. For JGS524PE, update to a version released after 2017-05-11. For GS105Ev2, update to a version released after 2017-05-11. For GS105PE, update to a version released after 2017-05-11. For GS108Ev3, update to a version released after 2017-05-11. For GS108PEv3, update to a version released after 2017-05-11. For GS116Ev2, update to a version released after 2017-05-11. For GSS108E, update to a version released after 2017-05-11. For GSS116E, update to a version released after 2017-05-11. For XS708Ev2, update to a version released after 2017-05-11. For XS716E, update to a version released after 2017-05-11.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18862

Affected Products

Gs105Ev2
Gs105Pe
Gs108Ev3
Gs116Ev2
Gss108E
Gss116E
Jgs516Pe
Jgs524Ev2
Jgs524Pe
Xs708Ev2
Xs716E