First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear M4300-28g Firmware | <12.0.2.15 | |
Netgear M4300-28g | ||
Netgear M4300-52g Firmware | <12.0.2.15 | |
Netgear M4300-52g | ||
Netgear M4300-28g-poe\+ Firmware | <12.0.2.15 | |
Netgear M4300-28g-poe\+ | ||
Netgear M4300-52g-poe\+ Firmware | <12.0.2.15 | |
Netgear M4300-52g-poe\+ | ||
Netgear M4300-8x8f Firmware | <12.0.2.15 | |
Netgear M4300-8x8f | ||
Netgear M4300-12x12f Firmware | <12.0.2.15 | |
Netgear M4300-12x12f | ||
Netgear M4300-24x24f Firmware | <12.0.2.15 | |
Netgear M4300-24x24f | ||
Netgear M4300-24x Firmware | <12.0.2.15 | |
Netgear M4300-24x | ||
Netgear M4300-48x Firmware | <12.0.2.15 | |
Netgear M4300-48x | ||
Netgear M4200 Firmware | <12.0.2.15 | |
Netgear M4200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-18831.
The affected devices are M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, and M4300-24X.
The severity of the vulnerability is rated as high with a severity value of 4.8.
To fix the vulnerability, update the firmware of the affected NETGEAR devices to version 12.0.2.15 or later.
You can find more information about the vulnerability in the NETGEAR Security Advisory: https://kb.netgear.com/000049031/Security-Advisory-for-Vertical-Privilege-Escalation-on-Some-Fully-Managed-Switches-PSV-2017-1952