ZDI-24-515: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-5247.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-515?
The severity of ZDI-24-515 is rated at 8.8 according to the CVSS rating.
How do I fix ZDI-24-515?
To mitigate the ZDI-24-515 vulnerability, ensure that you apply the latest security patches provided by NETGEAR for the ProSAFE Network Management System.
What type of attacks can exploit ZDI-24-515?
ZDI-24-515 can be exploited by remote attackers to execute arbitrary code on affected installations.
Is authentication required to exploit ZDI-24-515?
Yes, authentication is required to exploit the ZDI-24-515 vulnerability.
Which product versions are affected by ZDI-24-515?
The vulnerability ZDI-24-515 affects installations of the NETGEAR ProSAFE Network Management System.