HTTP: Netgear ProSAFE NMS300 Multiple Denial of Service

This signature detects attempts to exploit a known vulnerability against Netgear ProSAFE NMS300. A successful attack can result in a denial-of-service condition.

Extended Description

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing the path parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12123.

Affected Products

Netgear prosafe_network_management_system

Short Name
HTTP:DOS:NETGEAR-PSAFE-NMS-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-27272 CVE-2021-27275 Denial Multiple NMS300 Netgear ProSAFE Service of
Release Date
04/07/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Netgear

CVSS Score

7.5

6.5

Found a potential security threat?