Vulnerabilities > CVE-2014-4864 - Credentials Management vulnerability in Netgear Prosafe Firmware

047910
CVSS 3.3 - LOW
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
low complexity
netgear
CWE-255

Summary

The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/135480/netgearGS105Ev2-xssbypassxsrf.txt
idPACKETSTORM:135480
last seen2016-12-05
published2016-01-28
reporterBenedikt Westermann
sourcehttps://packetstormsecurity.com/files/135480/Netgear-GS105Ev2-Authentication-Bypass-XSS-CSRF.html
titleNetgear GS105Ev2 Authentication Bypass / XSS / CSRF