CVE-2023-2383 is a cross-site scripting (XSS) vulnerability affecting the Netgear SRX5308 firewall, specifically versions up to 4.3.5-3, within its web management interface. An authenticated attacker can exploit this by manipulating the smtpServer.fromAddr argument in the firewall_logs_email.htm page. Rated with a CVSS score of 4.8 (Medium), the vulnerability requires high privileges (PR:H) and user interaction (UI:R) for exploitation, leading to low impact on confidentiality and integrity (C:L/I:L). The attack can be initiated remotely (AV:N). While public exploit details are available, there is no evidence of active exploitation, nor are there Metasploit or Nuclei modules. Community discussion and media coverage are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.5-3CPE matchmatch criteria | cpe:2.3:o:netgear:srx5308_firmware:4.3.5-3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.