Vulnerability Name: CVE-2017-18824 (CCN-180825) Assigned: 2017-09-27 Published: 2017-09-27 Updated: 2020-04-23 Summary: Certain NETGEAR devices are affected by directory traversal. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15. CVSS v3 Severity: 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N )2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N )3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-22 Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2017-18824 Source: XF Type: UNKNOWNnetgear-cve201718824-dir-traversal(180825) Source: CCN Type: NETGEAR Article ID: 000049041Security Advisory for Directory Traversal on Some Fully Managed Switches, PSV-2017-1942 Source: CONFIRM Type: Vendor Advisoryhttps://kb.netgear.com/000049041/Security-Advisory-for-Directory-Traversal-on-Some-Fully-Managed-Switches-PSV-2017-1942 Vulnerable Configuration: Configuration 1 :cpe:/o:netgear:m4300-28g_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-28g:-:*:*:*:*:*:*:* Configuration 2 :cpe:/o:netgear:m4300-52g_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-52g:-:*:*:*:*:*:*:* Configuration 3 :cpe:/o:netgear:m4300-28g-poe+_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-28g-poe+:-:*:*:*:*:*:*:* Configuration 4 :cpe:/o:netgear:m4300-52g-poe+_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-52g-poe+:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:netgear:m4300-8x8f_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-8x8f:-:*:*:*:*:*:*:* Configuration 6 :cpe:/o:netgear:m4300-12x12f_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-12x12f:-:*:*:*:*:*:*:* Configuration 7 :cpe:/o:netgear:m4300-24x24f_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-24x24f:-:*:*:*:*:*:*:* Configuration 8 :cpe:/o:netgear:m4300-24x_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-24x:-:*:*:*:*:*:*:* Configuration 9 :cpe:/o:netgear:m4300-48x_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4300-48x:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:netgear:m4200_firmware:*:*:*:*:*:*:*:* (Version < 12.0.2.15)AND cpe:/h:netgear:m4200:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:netgear:m4300-24x_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-52g-poe+_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-52g_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-28g_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-8x8f_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-24x24f_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-28g-poe+_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4200_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-48x_firmware:12.0.2:*:*:*:*:*:*:* OR cpe:/o:netgear:m4300-12x12f_firmware:12.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
netgear m4300-28g firmware *
netgear m4300-28g -
netgear m4300-52g firmware *
netgear m4300-52g -
netgear m4300-28g-poe+ firmware *
netgear m4300-28g-poe+ -
netgear m4300-52g-poe+ firmware *
netgear m4300-52g-poe+ -
netgear m4300-8x8f firmware *
netgear m4300-8x8f -
netgear m4300-12x12f firmware *
netgear m4300-12x12f -
netgear m4300-24x24f firmware *
netgear m4300-24x24f -
netgear m4300-24x firmware *
netgear m4300-24x -
netgear m4300-48x firmware *
netgear m4300-48x -
netgear m4200 firmware *
netgear m4200 -
netgear m4300-24x firmware 12.0.2
netgear m4300-52g-poe+ firmware 12.0.2
netgear m4300-52g firmware 12.0.2
netgear m4300-28g firmware 12.0.2
netgear m4300-8x8f firmware 12.0.2
netgear m4300-24x24f firmware 12.0.2
netgear m4300-28g-poe+ firmware 12.0.2
netgear m4200 firmware 12.0.2
netgear m4300-48x firmware 12.0.2
netgear m4300-12x12f firmware 12.0.2