PT-2023-3788 · NetGear · Netgear Prosafe Network Management System

Steven Seeley

·

Published

2023-02-08

·

Updated

2024-09-18

·

CVE-2023-38096

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NETGEAR ProSAFE Network Management System (affected versions not specified)
Description This issue allows remote attackers to bypass authentication on affected installations of the NETGEAR ProSAFE Network Management System. The specific flaw exists within the MyHandlerInterceptor class, resulting from improper implementation of the authentication mechanism. An attacker can leverage this vulnerability to bypass authentication on the system, potentially impacting the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04079
CVE-2023-38096
ZDI-23-920

Affected Products

Netgear Prosafe Network Management System