Remote File Deletion in NETGEAR ProSAFE Network Management System
CVE-2021-27272
7.1HIGH
Key Information:
- Vendor
- Netgear
- Vendor
- CVE Published:
- 29 March 2021
Summary
This vulnerability enables remote attackers to delete arbitrary files on installations of the NETGEAR ProSAFE Network Management System version 1.6.0.26. Although the attack requires authentication, the authentication mechanism can be circumvented. The flaw lies in the processing of the path parameter within the ReportTemplateController class, where user-supplied input is not sufficiently validated before being utilized in file operations. An attacker can exploit this issue to induce a denial-of-service condition on the system, potentially disrupting service availability.
Affected Version(s)
ProSAFE Network Management System 1.6.0.26
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
rgod