CVE-2013-4775

UnknownEPSS 14.96%

Last modified

CVE-2013-4775 is a vulnerability of currently unknown severity. NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.. EPSS estimates a 14.96% chance of exploitation in the next 30 days.

Description

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.

Metrics

EPSS Probability
14.96%

96.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearProsafe Firmware5.3.0.17
NetgearProsafe Gs725tsAll versions
NetgearProsafe Gs728tpsAll versions
NetgearProsafe Gs728tsAll versions
NetgearProsafe Gs752tpsAll versions
NetgearProsafe Firmware<= 5.4.1.13
NetgearProsafe Firmware5.0.4.4
NetgearProsafe Firmware5.4.0.6
NetgearProsafe Firmware5.4.1.10
NetgearProsafe Gs724tv3
NetgearProsafe S716tv2
NetgearProsafe Firmware6.1.0.12
NetgearProsafe Gs728txsAll versions
NetgearProsafe Gs752txsAll versions
NetgearProsafe Firmware<= 5.4.1.14
NetgearProsafe Firmware5.4.1.13
NetgearProsafe Gs748tv4
NetgearProsafe Gs510tpAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-4775?
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.
How severe is CVE-2013-4775?
Severity scoring for CVE-2013-4775 is pending analysis. The EPSS model estimates a 14.96% probability of exploitation in the next 30 days.
How do I fix CVE-2013-4775?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-4775?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST