CVE-2020-35229: High severity netgear gs116e vulnerability
Published Mar 10, 2021
·Updated
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.
Affected Software
4 affected components
Netgear Gs116e Firmware=2.6.0.43
Netgear GS116E=v2
Netgear Jgs516pe Firmware=2.6.0.43
Netgear JGS516PE
Event History
Mar 10, 2021
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35229?
CVE-2020-35229 is a vulnerability that allows attackers to gain administrative privileges on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices.
2
How severe is CVE-2020-35229?
CVE-2020-35229 has a severity rating of 8.8 (high).
3
How can an attacker exploit CVE-2020-35229?
Attackers can exploit CVE-2020-35229 by reusing the authentication token required for NSDP write requests.
4
Which devices are affected by CVE-2020-35229?
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices are affected by CVE-2020-35229.
5
Is the NETGEAR GS116E device vulnerable to CVE-2020-35229?
No, the NETGEAR GS116E device is not vulnerable to CVE-2020-35229.