CVE-2013-4775

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:prosafe_firmware:5.3.0.17:*:*:*:*:*:*:*
OR cpe:2.3:h:netgear:prosafe_gs725ts:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs728tps:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs728ts:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs752tps:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:netgear:prosafe_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.0.4.4:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.3.0.17:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.4.0.6:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.4.1.10:*:*:*:*:*:*:*
OR cpe:2.3:h:netgear:prosafe_gs724t:v3:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_s716t:v2:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:prosafe_firmware:6.1.0.12:*:*:*:*:*:*:*
OR cpe:2.3:h:netgear:prosafe_gs728txs:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs752txs:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:netgear:prosafe_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.0.4.4:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.3.0.17:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.4.0.6:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.4.1.10:*:*:*:*:*:*:*
cpe:2.3:o:netgear:prosafe_firmware:5.4.1.13:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs748t:v4:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:prosafe_firmware:5.4.0.6:*:*:*:*:*:*:*
cpe:2.3:h:netgear:prosafe_gs510tp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:56

Type Values Removed Values Added
References () http://www.encripto.no/forskning/whitepapers/Netgear_prosafe_advisory_aug_2013.pdf - Exploit () http://www.encripto.no/forskning/whitepapers/Netgear_prosafe_advisory_aug_2013.pdf - Exploit

Information

Published : 2013-12-19 04:24

Updated : 2024-11-21 01:56


NVD link : CVE-2013-4775

Mitre link : CVE-2013-4775

CVE.ORG link : CVE-2013-4775


JSON object : View

Products Affected

netgear

  • prosafe_firmware
  • prosafe_gs728txs
  • prosafe_gs510tp
  • prosafe_gs724t
  • prosafe_gs728tps
  • prosafe_gs728ts
  • prosafe_s716t
  • prosafe_gs725ts
  • prosafe_gs748t
  • prosafe_gs752txs
  • prosafe_gs752tps
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor