NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability
CVE-2023-38099
Summary
A critical SQL injection vulnerability has been identified in the getNodesByTopologyMapSearch function of the NETGEAR ProSAFE Network Management System. The flaw originates from insufficient validation of user-supplied input used in SQL query construction, enabling remote attackers to exploit it to execute arbitrary code on compromised installations. Although the vulnerability requires user authentication, the existing authentication mechanism is susceptible to bypass, allowing unauthorized access. Successful exploitation can lead to executing commands in the context of the SYSTEM user, posing significant risks to sensitive data and system integrity.
Affected Version(s)
ProSAFE Network Management System 1.7.0.12 (Win64)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved