[Japanese]
|
JVNDB-2017-000055
|
NETGEAR ProSAFE Plus Configuration Utility vulnerable to improper access control
|
ProSAFE Plus Configuration Utility provided by NETGEAR is a Windows application to configure and manage NETGEAR's ProSAFE Plus and Click Switches. An operator uses the utility to login and configure NETGEAR switches.
When the utility is invoked, it starts listening on a certain port for SOAP requests. The utility executes configuration tasks for switches according to the SOAP requests.
The utility accepts connections from network, hence unintended operation may be conducted on the switches through the utility (CWE-284).
Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 3.4 (Low) [IPA Score]
- Attack Vector: Adjacent Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
CVSS V2 Severity: Base Metrics 2.9 (Low) [IPA Score]
- Access Vector: Adjacent Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
NETGEAR
- ProSAFE Plus Configuration Utility prior to 2.3.29
|
|
The Configuration Utility may be manipulated by some unexpected SOAP requests to configure the connected switch.
|
[Update the Software]
Update to the latest version according to the information provided by the developer.
|
NETGEAR
|
- Permissions(CWE-264) [IPA Evaluation]
|
- CVE-2017-2137
|
- JVN : JVN#08740778
- National Vulnerability Database (NVD) : CVE-2017-2137
|
- [2017/04/18]
Web page was published
[2017/06/01]
References : Content was added
|