CVE-2023-38096

NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerInterceptor class. The issue results from improper implementation of the authentication mechanism. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-19718.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*

History

06 Feb 2025, 18:01

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 - () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-23-920/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-920/ - Third Party Advisory
CPE cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*
First Time Netgear prosafe Network Management System
Netgear

21 Nov 2024, 08:12

Type Values Removed Values Added
References () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 - () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 -
References () https://www.zerodayinitiative.com/advisories/ZDI-23-920/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-920/ -

18 Sep 2024, 19:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de omisión de autenticación MyHandlerInterceptor del sistema de gestión de red NETGEAR ProSAFE. Esta vulnerabilidad permite a atacantes remotos eludir la autenticación en las instalaciones afectadas de NETGEAR ProSAFE Network Management System. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe dentro de la clase MyHandlerInterceptor. El problema se debe a una implementación incorrecta del mecanismo de autenticación. Un atacante puede aprovechar esta vulnerabilidad para eludir la autenticación en el sistema. Fue ZDI-CAN-19718.
Summary (en) NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerInterceptor class. The issue results from improper implementation of the authentication mechanism. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19718. (en) NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerInterceptor class. The issue results from improper implementation of the authentication mechanism. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-19718.

03 May 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-03 02:15

Updated : 2025-02-06 18:01


NVD link : CVE-2023-38096

Mitre link : CVE-2023-38096

CVE.ORG link : CVE-2023-38096


JSON object : View

Products Affected

netgear

  • prosafe_network_management_system
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo