CVE-2023-38099

NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getNodesByTopologyMapSearch function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19723.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*

History

06 Feb 2025, 18:01

Type Values Removed Values Added
CPE cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*
First Time Netgear prosafe Network Management System
Netgear
References () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 - () https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-23-917/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-917/ - Third Party Advisory

Information

Published : 2024-05-03 02:15

Updated : 2025-02-06 18:01


NVD link : CVE-2023-38099

Mitre link : CVE-2023-38099

CVE.ORG link : CVE-2023-38099


JSON object : View

Products Affected

netgear

  • prosafe_network_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')