📦 Prosafe Network Management System

by Netgear

🔍 What is Prosafe Network Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-50231

CRITICAL CVSS 9.6 May 3, 2024

This is a stored cross-site scripting (XSS) vulnerability in NETGEAR ProSAFE Network Management System that allows remote attackers to inject malicious scripts via the saveNodeLabel method. When explo...

CVE-2023-38096

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows remote attackers to bypass authentication on NETGEAR ProSAFE Network Management System installations without requiring any credentials. The flaw exists in the MyHandlerInterc...

CVE-2023-49693

CRITICAL CVSS 9.8 Nov 29, 2023

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on NETGEAR ProSAFE Network Management System devices by exploiting the exposed Java Debug Wire Protocol (JDWP) serv...

CVE-2021-27274

CRITICAL CVSS 9.8 Mar 29, 2021

This is an unauthenticated remote code execution vulnerability in NETGEAR ProSAFE Network Management System. Attackers can upload malicious files and execute arbitrary code with SYSTEM privileges with...

CVE-2024-6813

HIGH CVSS 8.8 Aug 21, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands on NETGEAR ProSAFE Network Management System installations, potentially leading to remote code execution with...

CVE-2024-5505

HIGH CVSS 8.8 Jun 6, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges on NETGEAR ProSAFE Network Management System installations. Attackers can exploit a directory ...

CVE-2024-5247

HIGH CVSS 8.8 May 23, 2024

This vulnerability allows authenticated remote attackers to upload arbitrary files to NETGEAR ProSAFE Network Management System installations, leading to remote code execution with SYSTEM privileges. ...

CVE-2024-5245

HIGH CVSS 7.8 May 23, 2024

This vulnerability allows local attackers with low-privileged access to escalate to SYSTEM privileges on NETGEAR ProSAFE Network Management System installations. Attackers can exploit default MySQL cr...

CVE-2023-44449

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to perform SQL injection through the clearAlertByIds function in NETGEAR ProSAFE Network Management System. Successful exploitation enables pri...

CVE-2023-41182

HIGH CVSS 8.8 May 3, 2024

This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and execute arbitrary code with SYSTEM privileges via directory traversal in the...

CVE-2023-38102

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated attackers to bypass authorization checks in NETGEAR ProSAFE Network Management System's createUser function, enabling privilege escalation to administrative res...

CVE-2023-38098

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to bypass authentication and upload arbitrary files to NETGEAR ProSAFE Network Management System, leading to remote code execution with SYSTEM ...

CVE-2023-38100

HIGH CVSS 8.8 May 3, 2024

This SQL injection vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication mechanisms and escalate privileges to access protected resources. ...

CVE-2023-38095

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to bypass authentication and upload arbitrary files to NETGEAR ProSAFE Network Management System, leading to remote code execution with SYSTEM ...

CVE-2021-27273

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on NETGEAR ProSAFE Network Management System installations. Attackers can bypass authentication ...

CVE-2021-27276

HIGH CVSS 7.1 Mar 29, 2021

This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and delete arbitrary files via path traversal in the realName parameter. It affe...