CVE-2017-18858 Information

Description

Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier M4300-28G 12.0.2.11 and earlier M4300-52G 12.0.2.11 and earlier M4300-28G-POE+ 12.0.2.11 and earlier M4300-52G-POE+ 12.0.2.11 and earlier M4300-8X8F 12.0.2.11 and earlier M4300-12X12F 12.0.2.11 and earlier M4300-24X24F 12.0.2.11 and earlier M4300-24X 12.0.2.11 and earlier and M4300-48X 12.0.2.11 and earlier.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://kb.netgear.com/000038655/Security-Advisory-for-Unauthenticated-Remote-Code-Execution-on-M4200-and-M4300-PSV-2017-1971

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: