| Vulnerability Name: | CVE-2020-5621 (CCN-187496) | ||||||||||||
| Assigned: | 2020-08-28 | ||||||||||||
| Published: | 2020-08-28 | ||||||||||||
| Updated: | 2020-09-04 | ||||||||||||
| Summary: | Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the device via unspecified vectors. | ||||||||||||
| CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-352 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2020-5621 Source: CCN Type: JVN#29903998 Multiple NETGEAR switching hubs vulnerable to cross-site request forgery Source: JVN Type: Third Party Advisory JVN#29903998 Source: XF Type: UNKNOWN netgear-cve20205621-csrf(187496) Source: MISC Type: Third Party Advisory https://jvn.jp/en/jp/JVN29903998/index.html Source: MISC Type: Patch, Vendor Advisory https://www.netgear.com/support/product/gs716Tv2.aspx Source: CCN Type: NETGEAR Web site GS716Tv3 16-Port Gigabit Ethernet Smart Managed Pro Switch with 2 SFP Ports Source: MISC Type: Patch, Vendor Advisory https://www.netgear.com/support/product/gs724tv3.aspx | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||