Information disclosure in JGS516PE and GS116Ev2 - CVE-2020-35222
Published: March 11, 2021
JGS516PE
GS116Ev2
NETGEAR
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the NSDP protocol does not require authentication to query for configuration parameters when the protocol is active. A remote attacker on the local network can obtain all the switch configuration parameters by sending the corresponding read requests.