Skip to main content

Vendor/product archive

netgear / prosafe_network_management_system CVEs

Beta · best-effort

24 CVEs tagged to netgear / prosafe_network_management_system4 Critical, 20 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-6814

Published Aug 21, 2024

NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6813

Published Aug 21, 2024

NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5505

Published Jun 6, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5247

Published May 23, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5245

Published May 23, 2024

NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affecte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50231

Published May 3, 2024

NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-44450

Published May 3, 2024

NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44449

Published May 3, 2024

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on af…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41182

Published May 3, 2024

NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-38102

Published May 3, 2024

NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38101

Published May 3, 2024

NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38100

Published May 3, 2024

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on af…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38099

Published May 3, 2024

NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38098

Published May 3, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38097

Published May 3, 2024

NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38096

Published May 3, 2024

NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38095

Published May 3, 2024

NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49694

Published Nov 29, 2023

A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application dire…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49693

Published Nov 29, 2023

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27276

Published Mar 29, 2021

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is re…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27275

Published Mar 29, 2021

This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27274

Published Mar 29, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not require…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27273

Published Mar 29, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27272

Published Mar 29, 2021

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is re…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1