7.8
CVSSv2

CVE-2013-4775

Published: 19/12/2013 Updated: 19/12/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and previous versions; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote malicious users to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.

Vulnerable Product Search on Vulmon Subscribe to Product

netgear prosafe_firmware 5.3.0.17

netgear prosafe_gs728tps -

netgear prosafe_gs752tps -

netgear prosafe_gs725ts -

netgear prosafe_gs728ts -

netgear prosafe_firmware

netgear prosafe_firmware 5.4.1.10

netgear prosafe_firmware 5.4.0.6

netgear prosafe_firmware 5.0.4.4

netgear prosafe_gs724t v3

netgear prosafe_s716t v2

netgear prosafe_firmware 6.1.0.12

netgear prosafe_gs728txs -

netgear prosafe_gs752txs -

netgear prosafe_firmware 5.4.1.13

netgear prosafe_gs748t v4

netgear prosafe_gs510tp -

Exploits

#!/usr/bin/python ################################################################ # # # Netgear ProSafe - CVE-2013-4775 PoC # # written by Juan J Guelfo @ Encripto AS # # post@encriptono # # ...