Serious flaws found in Netgear's NMS300 network management system

The flaws could lead to remote code execution with system privileges and arbitrary file download

Serious vulnerabilities in the Netgear NMS300 ProSafe network management system, an application used to discover, monitor and configure a wide range of network devices, can allow hackers to take control of the servers it's running on.

The NMS300 can be installed on Windows XP, 7, 8, 10, as well as Windows Server 2003, 2008 and 2012. It allows network administrators to centrally manage network switches, routers, wireless access points, printers, network-attached storage systems, firewall appliances and other devices that support SNMP (Simple Network Management Protocol).

The software is free for managing up to 200 devices and provides an easy-to-use Web graphical interface that can be accessed remotely.

Pedro Ribeiro, a researcher with U.K.-based security consultancy Agile Information Security, found that the Web interface of the Netgear NMS300 allows unauthenticated users to upload and then execute arbitrary Java files. Since the NMS300 software runs under the system account on the underlying OS, the rogue Java code would be executed with system privileges.

Ribeiro also found a second vulnerability that would allow an attacker to force the NMS300 application to load any file from the underlying server and then make it available for download in a predictable location. This means an attacker could read any sensitive file from the server.

Ribeiro reported these issues to Netgear through the CERT Coordination Center at Carnegie Mellon University, which published an advisory about them on Wednesday. The latest NMS300 software, version 1.5.0.11, is affected and there are currently no patches available from Netgear.

CERT/CC recommends that administrators implement firewall rules to restrict access to the application's Web interface. Exposing the NMS300 to the Internet or to untrusted local networks should be avoided, Ribeiro said in an email sent to the Full Disclosure mailing list.

The implications of these vulnerabilities can be very serious because, according to its official specifications, the NMS300 system can modify the configurations of the managed devices and even automatically install firmware updates on them. This means that attackers who compromise the NMS300 application could also potentially compromise some of the devices that it manages or to open up additional holes in the network by modifying their configurations.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?