High severity7.8NVD Advisory· Published Nov 29, 2023· Updated Jun 17, 2026
CVE-2023-49694
CVE-2023-49694
Description
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:netgear:prosafe_network_management_system:*:*:*:*:*:*:*:*range: <1.7.0.31
- (no CPE)
- Range: 0
Patches
Vulnerability mechanics
References
2- www.tenable.com/security/research/tra-2023-39nvdExploitVendor Advisory
- kb.netgear.com/000065885/Security-Advisory-for-Vertical-Privilege-Escalation-on-the-NMS300-PSV-2023-0127nvdVendor Advisory
News mentions
0No linked articles in our index yet.