RULE(RULE ID:322738)

Rule General Information
Release Date: 2019-07-11
Rule Name: Netgear ProSafe startup-config Information Disclosure Vulnerability (CVE-2013-4775)
Severity:
CVE ID:
Rule Protection Details
Description: NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://www.encripto.no/forskning/whitepapers/Netgear_prosafe_advisory_aug_2013.pdf
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.netgear.com/