CVE-2020-35221: Weak Encryption
The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35221?
CVE-2020-35221 is a vulnerability in the hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices.
What is the severity of CVE-2020-35221?
CVE-2020-35221 has a severity rating of 8.8 (high).
How does CVE-2020-35221 affect NETGEAR devices?
CVE-2020-35221 affects NETGEAR JGS516PE/GS116Ev2v2.6.0.43 devices by allowing attackers to generate valid passwords or infer parts of the original password.
Is NETGEAR Gs116e vulnerable to CVE-2020-35221?
NETGEAR Gs116e devices with firmware version 2.6.0.43 are vulnerable to CVE-2020-35221.
How can I fix CVE-2020-35221?
To fix CVE-2020-35221, it is recommended to update the firmware of affected NETGEAR devices to a secure version.