Stored Cross-Site Scripting Vulnerability in NETGEAR Managed Switches
CVE-2017-18825
5.2MEDIUM
Summary
Certain NETGEAR managed switches are susceptible to a stored XSS vulnerability. This issue allows attackers to inject malicious scripts that can affect users accessing the web interface. Devices such as the M4300 series and M4200 model prior to version 12.0.2.15 are impacted. It is crucial for users to apply the recommended firmware updates to mitigate this risk and enhance overall security.
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved