SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4775

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12…

HIGH 7.8EPSS 15.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS
14.96% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
netgear/prosafe firmware · netgear/prosafe gs725ts · netgear/prosafe gs728tps · netgear/prosafe gs728ts · netgear/prosafe gs752tps · netgear/prosafe gs724t · netgear/prosafe s716t · netgear/prosafe gs728txs · netgear/prosafe gs752txs · netgear/prosafe gs748t · netgear/prosafe gs510tp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.