Lucene search

K
cveJpcertCVE-2020-5621
HistoryAug 28, 2020 - 5:15 a.m.

CVE-2020-5621

2020-08-2805:15:11
CWE-352
jpcert
web.nvd.nist.gov
31
cve-2020-5621
csrf
netgear
switching hubs
gs716tv2
gs724tv3
firmware
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.8

Confidence

High

EPSS

0.002

Percentile

57.5%

Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the device via unspecified vectors.

Affected configurations

Nvd
Vulners
Node
netgeargs716tMatchv2
AND
netgeargs716tv2_firmwareRange5.4.2.30
Node
netgeargs724tMatchv3
AND
netgeargs724tv3_firmwareRange5.4.2.30
VendorProductVersionCPE
netgeargs716tv2cpe:2.3:h:netgear:gs716t:v2:*:*:*:*:*:*:*
netgeargs716tv2_firmware*cpe:2.3:o:netgear:gs716tv2_firmware:*:*:*:*:*:*:*:*
netgeargs724tv3cpe:2.3:h:netgear:gs724t:v3:*:*:*:*:*:*:*
netgeargs724tv3_firmware*cpe:2.3:o:netgear:gs724tv3_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Multiple NETGEAR switching hubs",
    "vendor": "Neuroinformatics Unit, Integrative Computational Brain Science Collaboration Division, RIKEN Center for Brain Science",
    "versions": [
      {
        "status": "affected",
        "version": "GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.8

Confidence

High

EPSS

0.002

Percentile

57.5%

Related for CVE-2020-5621