CVE-2017-2137
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: vultures@jpcert.or.jp — https://kb.netgear.com/000038443/Security-Advisory-for-Insecure-SOAP-Access-in-ProSAFE-Plus-Configuration-Utility-PSV-2017-1997
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netgear | prosafe_plus_configuration_utility | {"endIncluding":"2.3.28"} | |
References
- http://jvn.jp/en/jp/JVN08740778/index.html
- https://kb.netgear.com/000038443/Security-Advisory-for-Insecure-SOAP-Access-in-ProSAFE-Plus-Configuration-Utility-PSV-2017-1997
- http://jvn.jp/en/jp/JVN08740778/index.html
- https://kb.netgear.com/000038443/Security-Advisory-for-Insecure-SOAP-Access-in-ProSAFE-Plus-Configuration-Utility-PSV-2017-1997
Verify integrity in audit chain (admin only). AS-IS.