Vulnerability record · CVE-2023-38096 · published 3 May 2024
CVE-2023-38096: NETGEAR ProSAFE NMS MyHandlerInterceptor authentication bypass
Netgear · Prosafe Network Management System
The NETGEAR ProSAFE Network Management System contains an authentication bypass in the MyHandlerInterceptor class caused by improper implementation of the authentication mechanism. A remote, unauthenticated attacker can bypass authentication on affected installations, which matters because the system is a management plane component with high confidentiality, integrity and availability impact per the CVSS vector.
Description
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MyHandlerInterceptor class. The issue results from improper implementation of the authentication mechanism. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-19718.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a critical management-plane exposure despite the absence of KEV listing.
What it is
The NETGEAR ProSAFE Network Management System contains an authentication bypass in the MyHandlerInterceptor class caused by improper implementation of the authentication mechanism. A remote, unauthenticated attacker can bypass authentication on affected installations, which matters because the system is a management plane component with high confidentiality, integrity and availability impact per the CVSS vector.
Impact
An attacker gains unauthenticated access to the management system, effectively obtaining the privileges of a legitimate user and the ability to read and modify managed network configuration and data. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N) required. The flaw is in the MyHandlerInterceptor authentication handler, so any request path routed through that interceptor is potentially affected.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.82035, 99.6th percentile), indicating strong predicted likelihood of exploitation, but the record contains no public exploit or in-the-wild confirmation.
What to do
- Apply the NETGEAR vendor advisory fix for PSV-2023-0024/PSV-2023-0025 (kb.netgear.com/000065707) as the first action.
- If patching cannot be done immediately, restrict network access to the ProSAFE NMS management interface to trusted administrative networks only.
- Place the NMS behind a firewall or VPN and block direct internet exposure of its web interface.
- Audit and rotate credentials and review configuration for unauthorized changes made through the management system.
- Monitor the vendor advisory and ZDI-23-920 for updated guidance.
Detection
- Review web server and application logs for requests that reach protected handlers without a prior successful authentication event.
- Alert on anomalous or unexpected administrative actions and configuration changes in the NMS audit trail.
- Monitor network traffic to the NMS management port from untrusted or unexpected source addresses.
- Correlate NMS access logs with authentication logs to find sessions with no matching login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-38096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.