A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53628 | A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM. |
Fixes
Solution
The issue has been fixed in NMS300 version 1.7.0.31
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-02T22:01:25.766Z
Reserved: 2023-11-29T22:03:49.958Z
Link: CVE-2023-49694
No data.
Status : Modified
Published: 2023-11-29T23:15:20.750
Modified: 2024-11-21T08:33:42.957
Link: CVE-2023-49694
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD