Stored XSS Vulnerability in NETGEAR Fully Managed Switches
CVE-2017-18839
5.2MEDIUM
Summary
A stored cross-site scripting (XSS) vulnerability exists in certain NETGEAR fully managed switches, affecting the M4300 and M4200 series. By exploiting this weakness, an attacker could inject malicious scripts into the system, potentially compromising user sessions or redirecting users to harmful sites. The affected devices include various models, all prior to software version 12.0.2.15. Users are urged to update their firmware to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved