CVE-2020-35225: Medium severity netgear gs116e vulnerability
Published Mar 10, 2021
·Updated
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of service attacks.
Affected Software
4 affected components
Netgear Gs116e Firmware=2.6.0.43
Netgear GS116E=v2
Netgear Jgs516pe Firmware=2.6.0.43
Netgear JGS516PE
Event History
Mar 10, 2021
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35225.
2
What is the severity level of CVE-2020-35225?
The severity level of CVE-2020-35225 is medium with a score of 6.8.
3
Which devices are affected by CVE-2020-35225?
NETGEAR JGS516PE and GS116Ev2 v2.6.0.43 devices are affected by CVE-2020-35225.
4
What is the impact of CVE-2020-35225?
CVE-2020-35225 could potentially allow denial of service attacks.
5
Is there a fix available for CVE-2020-35225?
Please refer to the official reference for information on available fixes for CVE-2020-35225: https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/