ZDI-CAN-22951: ZDI-24-515: NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
Published May 24, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-5247.
Affected Software
1 affected component
Netgear ProSAFE Network Management System
Event History
May 24, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22951?
ZDI-CAN-22951 has been assigned a CVSS rating of 8.8, indicating a high severity level.
2
How do I fix ZDI-CAN-22951?
To fix ZDI-CAN-22951, update your NETGEAR ProSAFE Network Management System to the latest version provided by NETGEAR.
3
What type of attack does ZDI-CAN-22951 enable?
ZDI-CAN-22951 enables remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-22951?
Yes, authentication is required to exploit the ZDI-CAN-22951 vulnerability.
5
Which software is affected by ZDI-CAN-22951?
ZDI-CAN-22951 affects installations of the NETGEAR ProSAFE Network Management System.