CVE-2020-35783: Medium severity netgear jgs516pe firmware vulnerability
Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48. The NSDP protocol version allows unauthenticated remote attackers to obtain all the switch configuration parameters by sending the corresponding read requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35783.
Which devices are affected by this vulnerability?
This vulnerability affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48.
What is the severity of CVE-2020-35783?
The severity of CVE-2020-35783 is medium with a CVSS score of 6.5.
How does this vulnerability impact the affected devices?
This vulnerability allows unauthenticated remote attackers to obtain all the switch configuration settings.
Is there a fix available for this vulnerability?
Yes, a firmware update is available to fix this vulnerability. Please refer to the vendor's security advisory for instructions.