Vulnerability Description
ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Prosafe Plus Configuration Utility | <= 2.3.28 |
References
- http://jvn.jp/en/jp/JVN08740778/index.htmlThird Party AdvisoryVDB Entry
- https://kb.netgear.com/000038443/Security-Advisory-for-Insecure-SOAP-Access-in-PVendor Advisory
- http://jvn.jp/en/jp/JVN08740778/index.htmlThird Party AdvisoryVDB Entry
- https://kb.netgear.com/000038443/Security-Advisory-for-Insecure-SOAP-Access-in-PVendor Advisory
FAQ
What is CVE-2017-2137?
CVE-2017-2137 is a vulnerability with a CVSS score of 3.7 (LOW). ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.
How severe is CVE-2017-2137?
CVE-2017-2137 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2137?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Prosafe Plus Configuration Utility.