CVE-2017-18838 Information

Description

Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15 M4300-52G before 12.0.2.15 M4300-28G-POE+ before 12.0.2.15 M4300-52G-POE+ before 12.0.2.15 M4300-8X8F before 12.0.2.15 M4300-12X12F before 12.0.2.15 M4300-24X24F before 12.0.2.15 M4300-24X before 12.0.2.15 M4300-48X before 12.0.2.15 and M4200 before 12.0.2.15.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://kb.netgear.com/000049024/Security-Advisory-for-Vertical-Privilege-Escalation-on-Some-Fully-Managed-Switches-PSV-2017-1975

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: