CVE-2020-35784

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and GS116Ev2 before 2.6.0.48.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
mitreCNA
6.2 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AC:H/AV:N/A:L/C:H/I:H/PR:H/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
netgearjgs516pe_firmware
𝑥
< 2.6.0.48
netgearjgs524e_firmware
𝑥
< 2.6.0.48
netgearjgs524pe_firmware
𝑥
< 2.6.0.48
netgeargs116e_firmware
𝑥
< 2.6.0.48
𝑥
= Vulnerable software versions