Vulnerability record · CVE-2023-50231 · published 3 May 2024
CVE-2023-50231: NETGEAR ProSAFE NMS saveNodeLabel stored XSS privilege escalation
Netgear · Prosafe Network Management System
The saveNodeLabel method in NETGEAR ProSAFE Network Management System fails to validate user-supplied data, allowing injection of arbitrary script. Because the flaw is a stored cross-site scripting issue in a management interface, it can be used to escalate privileges on affected installations. The vendor advisory and ZDI advisory confirm the issue but the record does not list specific affected versions.
Description
NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the saveNodeLabel method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-21838.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCVSS is critical (9.6) and EPSS is very high, but exploitation requires user interaction and no active exploitation is confirmed in KEV.
What it is
The saveNodeLabel method in NETGEAR ProSAFE Network Management System fails to validate user-supplied data, allowing injection of arbitrary script. Because the flaw is a stored cross-site scripting issue in a management interface, it can be used to escalate privileges on affected installations. The vendor advisory and ZDI advisory confirm the issue but the record does not list specific affected versions.
Impact
An attacker can execute script in the context of a victim user and escalate privileges to resources normally protected from that user. This can lead to compromise of the management system and any devices it controls.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires minimal user interaction (UI:R), meaning a victim must view or interact with the injected content. The scope is changed (S:C), so the impact can extend beyond the vulnerable component.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it. EPSS is high at 0.53303 (98.9th percentile), indicating a meaningful probability of exploitation activity, but the record does not confirm active exploitation.
What to do
- Apply the NETGEAR security advisory patch for the NMS300 referenced in PSV-2023-0106.
- Restrict network access to the ProSAFE NMS management interface to trusted administrative networks only.
- Require administrators to use dedicated, hardened browsers and avoid browsing untrusted sites while authenticated to the NMS.
- Monitor vendor advisories for updated affected version information and additional fixes.
Detection
- Review NMS application and web server logs for suspicious saveNodeLabel requests containing script tags or unusual encoded payloads.
- Monitor for unexpected administrative actions or privilege changes originating from NMS sessions.
- Search for known XSS payload patterns in stored node labels or other NMS-managed fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.netgear.com/000065901/Security-Advisory-for-Stored-Cross-Site-Scripting-on-the-NMS300-PSV-2023-0106 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1847/ | Third Party Advisory |
| https://kb.netgear.com/000065901/Security-Advisory-for-Stored-Cross-Site-Scripting-on-the-NMS300-PSV-2023-0106 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1847/ | Third Party Advisory |
Track CVE-2023-50231 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-50231), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.