CVE-2019-20697 describes a stack-based buffer overflow vulnerability affecting specific NETGEAR GS728 and GS752 series switches. An unauthenticated attacker can exploit this flaw, potentially leading to high impact on confidentiality, integrity, and availability of the affected device. With a CVSS score of 8.8 (High), this vulnerability can be exploited over the adjacent network with low attack complexity. While no public exploit code or active exploitation has been observed, and community discussion is minimal, affected organizations should prioritize patching to versions GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS750E before 1.0.1.4, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.0.48CPE matchmatch criteria | cpe:2.3:o:netgear:gs728tpp_firmware:*:*:*:*:*:*:*:* | ||
< 6.0.0.48CPE matchmatch criteria | cpe:2.3:o:netgear:gs728tp_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.4CPE matchmatch criteria | cpe:2.3:o:netgear:gs750e_firmware:*:*:*:*:*:*:*:* | ||
< 6.0.0.48CPE matchmatch criteria | cpe:2.3:o:netgear:gs752tpp_firmware:*:*:*:*:*:*:*:* | ||
< 6.0.0.48CPE matchmatch criteria | cpe:2.3:o:netgear:gs752tp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.