Vulnerability Name:

CCN-223515

Published:2022-03-31
Updated:2022-03-31
Summary:NETGEAR switches are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS v3 Severity:6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Cross-Site Scripting
References:Source: XF
Type: UNKNOWN
netgear-psv20210174-xss(223515)

Source: CCN
Type: NETGEAR Security Advisory: PSV-2021-0174
Security Advisory for Reflected Cross Site Scripting on Some Smart Managed Pro Switches

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/h:netgear:gs108t:v3:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs110tpp:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs110tp:v3:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs724tpp:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs724tp:v2:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs728tpp:v2:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs728tp:v2:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs752tp:v2:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:ms510txm:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:ms510txup:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs308t:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs752tpp:-:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:gs310tp:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    netgear gs108t v3
    netgear gs110tpp -
    netgear gs110tp v3
    netgear gs724tpp -
    netgear gs724tp v2
    netgear gs728tpp v2
    netgear gs728tp v2
    netgear gs752tp v2
    netgear ms510txm -
    netgear ms510txup -
    netgear gs308t -
    netgear gs752tpp -
    netgear gs310tp -