First published: Thu May 23 2024(Updated: )
NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of default MySQL credentials. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22755.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear ProSAFE Network Management Software 300 | <1.7.0.37 | |
Netgear ProSAFE Network Management Software 300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5245 is a critical vulnerability that enables local privilege escalation in NETGEAR ProSAFE Network Management System.
To fix CVE-2024-5245, ensure to apply the latest security patches provided by NETGEAR for ProSAFE Network Management System.
CVE-2024-5245 affects local users who have access to installations of NETGEAR ProSAFE Network Management System.
CVE-2024-5245 is classified as a local privilege escalation vulnerability.
No, CVE-2024-5245 requires local access to exploit the vulnerability.