Access Control Vulnerability in NETGEAR Smart Managed Plus Switches
CVE-2020-35784

6.2MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
30 December 2020

Summary

Certain NETGEAR Smart Managed Plus Switches are susceptible to access control issues at the function level. This vulnerability could allow unauthorized users to gain access to sensitive functions, potentially compromising network integrity and security. Devices affected include JGS516PE, JGS524PE, JGS524Ev2, and GS116Ev2, all on versions prior to 2.6.0.48. Users are strongly encouraged to upgrade to the latest firmware versions to mitigate this risk.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.