Vulnerability Description
Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | M4300-28G Firmware | < 12.0.2.15 |
| Netgear | M4300-28G | - |
| Netgear | M4300-52G Firmware | < 12.0.2.15 |
| Netgear | M4300-52G | - |
| Netgear | M4300-28G-Poe\+ Firmware | < 12.0.2.15 |
| Netgear | M4300-28G-Poe\+ | - |
| Netgear | M4300-52G-Poe\+ Firmware | < 12.0.2.15 |
| Netgear | M4300-52G-Poe\+ | - |
| Netgear | M4300-8X8F Firmware | < 12.0.2.15 |
| Netgear | M4300-8X8F | - |
| Netgear | M4300-12X12F Firmware | < 12.0.2.15 |
| Netgear | M4300-12X12F | - |
| Netgear | M4300-24X24F Firmware | < 12.0.2.15 |
| Netgear | M4300-24X24F | - |
| Netgear | M4300-24X Firmware | < 12.0.2.15 |
| Netgear | M4300-24X | - |
| Netgear | M4300-48X Firmware | < 12.0.2.15 |
| Netgear | M4300-48X | - |
| Netgear | M4200 Firmware | < 12.0.2.15 |
| Netgear | M4200 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000049024/Security-Advisory-for-Vertical-Privilege-EscalaVendor Advisory
- https://kb.netgear.com/000049024/Security-Advisory-for-Vertical-Privilege-EscalaVendor Advisory
FAQ
What is CVE-2017-18838?
CVE-2017-18838 is a vulnerability with a CVSS score of 7.8 (HIGH). Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M43...
How severe is CVE-2017-18838?
CVE-2017-18838 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18838?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear M4300-28G Firmware, Netgear M4300-28G, Netgear M4300-52G Firmware, Netgear M4300-52G, Netgear M4300-28G-Poe\+ Firmware.