Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-358m-5hx2-q7v5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.

The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.

EPSS

Процентиль: 13%
0.00044
Низкий

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость реализации протокола Netgear Switch Discovery Protocol (NSDP) микропрограммного обеспечения коммутаторов NETGEAR ProSAFE Plus JGS516PE и ProSAFE Plus GS116Ev2, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 13%
0.00044
Низкий

Дефекты

CWE-327