Access Control Vulnerability in NETGEAR Smart Managed Plus Switches
CVE-2020-35784
6.2MEDIUM
Summary
Certain NETGEAR Smart Managed Plus Switches are susceptible to access control issues at the function level. This vulnerability could allow unauthorized users to gain access to sensitive functions, potentially compromising network integrity and security. Devices affected include JGS516PE, JGS524PE, JGS524Ev2, and GS116Ev2, all on versions prior to 2.6.0.48. Users are strongly encouraged to upgrade to the latest firmware versions to mitigate this risk.
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved