First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear M4300-28g Firmware | <12.0.2.15 | |
Netgear M4300-28g | ||
Netgear M4300-52g Firmware | <12.0.2.15 | |
Netgear M4300-52g | ||
Netgear M4300-28g-poe\+ Firmware | <12.0.2.15 | |
Netgear M4300-28g-poe\+ | ||
Netgear M4300-52g-poe\+ Firmware | <12.0.2.15 | |
Netgear M4300-52g-poe\+ | ||
Netgear M4300-8x8f Firmware | <12.0.2.15 | |
Netgear M4300-8x8f | ||
Netgear M4300-12x12f Firmware | <12.0.2.15 | |
Netgear M4300-12x12f | ||
Netgear M4300-24x24f Firmware | <12.0.2.15 | |
Netgear M4300-24x24f | ||
Netgear M4300-24x Firmware | <12.0.2.15 | |
Netgear M4300-24x | ||
Netgear M4300-48x Firmware | <12.0.2.15 | |
Netgear M4300-48x | ||
Netgear M4200 Firmware | <12.0.2.15 | |
Netgear M4200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18822 is a vulnerability that affects certain NETGEAR devices, allowing for vertical privilege escalation.
NETGEAR devices M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, M4300-24x, M4300-48x, and M4200 are affected by CVE-2017-18822.
The severity of CVE-2017-18822 is high with a CVSS score of 7.8.
To fix CVE-2017-18822, update the firmware of the affected NETGEAR devices to version 12.0.2.15 or above. More information on how to update can be found in the provided reference link.
You can find more information about CVE-2017-18822 in the following reference link: [Netgear Security Advisory](https://kb.netgear.com/000049043/Security-Advisory-for-Vertical-Privilege-Escalation-on-Some-Fully-Managed-Switches-PSV-2017-1944).