CVE-2020-35784: High severity netgear jgs516pe firmware vulnerability
Published Dec 29, 2020
·Updated
Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and GS116Ev2 before 2.6.0.48.
Affected Software
8 affected components
Netgear Jgs516pe Firmware<2.6.0.48
Netgear JGS516PE
Netgear Jgs524e Firmware<2.6.0.48
Netgear JGS524E=v2
Netgear Jgs524pe Firmware<2.6.0.48
Netgear JGS524PE
Netgear Gs116e Firmware<2.6.0.48
Netgear GS116E=v2
Event History
Dec 29, 2020
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2020-35784?
CVE-2020-35784 is considered a moderate severity vulnerability due to the lack of access control at the function level.
2
How do I fix CVE-2020-35784?
To fix CVE-2020-35784, upgrade the affected NETGEAR devices to firmware version 2.6.0.48 or later.
3
Which NETGEAR devices are affected by CVE-2020-35784?
CVE-2020-35784 affects the JGS516PE, JGS524PE, JGS524Ev2, and GS116Ev2 models before firmware version 2.6.0.48.
4
What type of vulnerability is CVE-2020-35784?
CVE-2020-35784 is classified as an access control vulnerability at the function level.
5
Is CVE-2020-35784 a firmware issue?
Yes, CVE-2020-35784 is a firmware issue impacting certain versions of NETGEAR devices.