Reflected XSS Vulnerability in NETGEAR Managed Switches
CVE-2017-18834
6.1MEDIUM
Summary
NETGEAR managed switches, including several models from the M4300 series and M4200, are susceptible to a reflected cross-site scripting vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewable by users, potentially leading to session hijacking or exposure of sensitive information. Users are advised to upgrade their devices to versions 12.0.2.15 or later to mitigate this security risk. For more detailed information, refer to the official NETGEAR security advisory.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved