Remote File Deletion in NETGEAR ProSAFE Network Management System
CVE-2021-27272

7.1HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
29 March 2021

Summary

This vulnerability enables remote attackers to delete arbitrary files on installations of the NETGEAR ProSAFE Network Management System version 1.6.0.26. Although the attack requires authentication, the authentication mechanism can be circumvented. The flaw lies in the processing of the path parameter within the ReportTemplateController class, where user-supplied input is not sufficiently validated before being utilized in file operations. An attacker can exploit this issue to induce a denial-of-service condition on the system, potentially disrupting service availability.

Affected Version(s)

ProSAFE Network Management System 1.6.0.26

References

EPSS Score

14% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rgod
.