Reflected XSS Vulnerability in NETGEAR M4300 Series and M4200 Managed Switches
CVE-2017-18833

6.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
20 April 2020

Summary

NETGEAR's M4300 and M4200 series managed switches are susceptible to a reflected cross-site scripting issue, allowing attackers to inject malicious scripts into web pages viewed by users. This vulnerability impacts specific models that have not undergone the necessary firmware updates, making it essential for users to apply the latest patches to secure their network devices against potential exploitation. To learn more about securing these devices, refer to NETGEAR's security advisory.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.