Reflected Cross-Site Scripting Vulnerability in NETGEAR Fully Managed Switches
CVE-2017-18835

6.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
20 April 2020

Summary

Certain NETGEAR fully managed switches are susceptible to a reflected XSS vulnerability, enabling attackers to inject malicious scripts via specially crafted URLs. This flaw can affect models such as the M4300 series and the M4200 series prior to firmware version 12.0.2.15, potentially compromising the devices' integrity and the security of the network they serve. It is crucial for users to review the security advisory and apply recommended firmware updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.