CVE-2020-35784

EUVD-2020-23439
Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and GS116Ev2 before 2.6.0.48.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
mitreCNA
6.2 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AC:H/AV:N/A:L/C:H/I:H/PR:H/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
netgearjgs516pe_firmware
𝑥
< 2.6.0.48
netgearjgs524e_firmware
𝑥
< 2.6.0.48
netgearjgs524pe_firmware
𝑥
< 2.6.0.48
netgeargs116e_firmware
𝑥
< 2.6.0.48
𝑥
= Vulnerable software versions