CVE-2019-17049: SQL Injection
Published Sep 30, 2019
·Updated
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.
Affected Software
2 affected components
Netgear Srx5308 Firmware=4.3.5-3
Netgear SRX5308
Event History
Sep 30, 2019
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
Description
Frequently Asked Questions
1
What is CVE-2019-17049?
CVE-2019-17049 refers to a vulnerability found in NETGEAR SRX5308 4.3.5-3 devices that allows SQL Injection.
2
How severe is CVE-2019-17049?
CVE-2019-17049 has a severity rating of 7.5, which is considered high.
3
How does CVE-2019-17049 affect NETGEAR SRX5308 4.3.5-3 devices?
CVE-2019-17049 allows SQL Injection in NETGEAR SRX5308 4.3.5-3 devices, which can be exploited to add a new user account.
4
Is NETGEAR SRX5308 4.3.5-3 vulnerable to CVE-2019-17049?
Yes, NETGEAR SRX5308 4.3.5-3 devices are vulnerable to CVE-2019-17049.
5
How can I fix CVE-2019-17049 in NETGEAR SRX5308 4.3.5-3 devices?
To fix CVE-2019-17049, it is recommended to update the firmware of NETGEAR SRX5308 to a version that addresses the vulnerability.