ZDI-23-916: NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-916?
The severity of ZDI-23-916 is high due to its potential for privilege escalation.
How do I fix ZDI-23-916?
To fix ZDI-23-916, ensure that you apply the latest updates and patches provided by NETGEAR for the ProSAFE Network Management System.
Who is affected by ZDI-23-916?
ZDI-23-916 affects installations of the NETGEAR ProSAFE Network Management System that have not been updated.
Can ZDI-23-916 be exploited remotely?
Yes, ZDI-23-916 can be exploited remotely if an attacker can bypass the existing authentication mechanism.
What authentication issues are involved in ZDI-23-916?
ZDI-23-916 involves a vulnerability that allows attackers to bypass the authentication mechanism, leading to potential privilege escalation.