Vulnerability record · CVE-2023-44449 · published 3 May 2024
CVE-2023-44449: NETGEAR ProSAFE NMS clearAlertByIds SQL injection privilege escalation
Netgear · Prosafe Network Management System
The clearAlertByIds function in NETGEAR ProSAFE Network Management System builds SQL queries from user-supplied strings without proper validation, allowing SQL injection. An authenticated remote attacker can exploit this to escalate privileges and reach resources normally protected from their account.
Description
NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-21875.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (0.526, 99th percentile) make this a serious authenticated SQL injection, though it is not in KEV and requires valid credentials.
What it is
The clearAlertByIds function in NETGEAR ProSAFE Network Management System builds SQL queries from user-supplied strings without proper validation, allowing SQL injection. An authenticated remote attacker can exploit this to escalate privileges and reach resources normally protected from their account.
Impact
An attacker with a low-privileged account gains high confidentiality, integrity and availability impact, effectively escalating to administrative-level access over the management system.
Attack surface
Reachable over the network via the NMS web interface with a low-privileged authenticated session; no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at 0.526 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the NETGEAR security advisory fix for the NMS300 (PSV-2023-0114/PSV-2023-0115) as the first action.
- Restrict network access to the ProSAFE NMS management interface to trusted administrative networks.
- Audit and minimize accounts with access to the NMS, removing or downgrading unused low-privileged users.
- Monitor the vendor advisory and ZDI advisory for updated guidance and any revised affected versions.
Detection
- Review NMS web server and application logs for anomalous requests to the clearAlertByIds endpoint, especially SQL metacharacters in parameters.
- Alert on SQL error strings or unexpected database errors returned by the NMS application.
- Baseline normal NMS user activity and flag privilege changes or access to administrative functions by low-privileged accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-44449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.