[Japanese]

JVNDB-2017-000055

NETGEAR ProSAFE Plus Configuration Utility vulnerable to improper access control

Overview

ProSAFE Plus Configuration Utility provided by NETGEAR is a Windows application to configure and manage NETGEAR's ProSAFE Plus and Click Switches. An operator uses the utility to login and configure NETGEAR switches.
When the utility is invoked, it starts listening on a certain port for SOAP requests. The utility executes configuration tasks for switches according to the SOAP requests.
The utility accepts connections from network, hence unintended operation may be conducted on the switches through the utility (CWE-284).

Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 2.9 (Low) [IPA Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None

CVSS V3 Severity:
Base Metrics: 3.4 (Low) [IPA Score]
  • Access Vector: Adjacent
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: None
  • Integrity Impact: Low
  • Availability Impact: None
Affected Products


NETGEAR
  • ProSAFE Plus Configuration Utility prior to 2.3.29

Impact

The Configuration Utility may be manipulated by some unexpected SOAP requests to configure the connected switch.
Solution

[Update the Software]
Update to the latest version according to the information provided by the developer.
Vendor Information

NETGEAR
CWE (What is CWE?)

  1. Permissions(CWE-264) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2017-2137
References

  1. JVN : JVN#08740778
  2. National Vulnerability Database (NVD) : CVE-2017-2137
Revision History

[2017/04/18]
  Web page was published
[2017/06/01]
  References : Content was added