Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcp9-f3w5-gqqw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость реализации протокола NSDP микропрограммного обеспечения сетевых устройств Netgear ProSafe Plus JGS516PE и ProSAFE Plus GS116Ev2, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-384