PT-2023-2605 · NetGear · Netgear Srx5308

Leetsun

·

Published

2023-04-13

·

Updated

2024-05-17

·

CVE-2023-2387

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Netgear SRX5308 versions up to 4.3.5-3
Description A vulnerability was found in the Web Management Interface of Netgear SRX5308, due to insufficient input validation. This allows a remote attacker to conduct a cross-site scripting attack by sending a specially crafted HTTP request using the dhcp.winsServer1 parameter. The attack can be launched remotely and the exploit has been disclosed to the public.
Recommendations For Netgear SRX5308 versions up to 4.3.5-3, as a temporary workaround, consider restricting access to the Web Management Interface until a patch is available. Avoid using the dhcp.winsServer1 parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-02437
CVE-2023-2387

Affected Products

Netgear Srx5308