A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.
References
Configurations
History
21 Nov 2024, 05:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/ - Vendor Advisory |
Information
Published : 2021-03-10 19:15
Updated : 2024-11-21 05:27
NVD link : CVE-2020-35227
Mitre link : CVE-2020-35227
CVE.ORG link : CVE-2020-35227
JSON object : View
Products Affected
netgear
- jgs516pe_firmware
- gs116e_firmware
- jgs516pe
- gs116e
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')