PT-2021-2875 · NetGear · Netgear Jgs516Pe/Gs116Ev2

Published

2021-03-08

·

Updated

2021-07-21

·

CVE-2020-35221

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR JGS516PE/GS116Ev2 version 2.6.0.43
Description The hashing algorithm used for NSDP password authentication is insecure, allowing attackers with network capture access to generate collisions and infer parts of the original password, or create valid passwords. This issue is related to the implementation of the Netgear Switch Discovery Protocol (NSDP) in the firmware of NETGEAR ProSAFE Plus switches, which contains defects in its hashing algorithm. Exploitation of this issue may allow a remote attacker to elevate their privileges.
Recommendations For version 2.6.0.43, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Use of a Broken Cryptographic Algorithm

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02436
CVE-2020-35221

Affected Products

Netgear Jgs516Pe/Gs116Ev2