CVE-2020-35229 affects NETGEAR JGS516PE and GS116Ev2 switches, specifically firmware version 2.6.0.43. This vulnerability allows attackers on the same network to reuse invalidated authentication tokens for NSDP write requests, effectively gaining administrative privileges. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there are no known public exploits or Metasploit modules, the vulnerability has received limited community discussion and media coverage, indicating a lower profile despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0.43CPE matchmatch criteria | cpe:2.3:o:netgear:gs116e_firmware:2.6.0.43:*:*:*:*:*:*:* | ||
2.6.0.43CPE matchmatch criteria | cpe:2.3:o:netgear:jgs516pe_firmware:2.6.0.43:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.