NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Chipperchoi's avatar
Chipperchoi
Aspirant
May 03, 2021

Amnesia:33 vulnerabilities for JGS516PE

Hello all,

 

I am not having much luck in finding any information regarding the Amnesia:33 vulnerabilities showing up on our Qualys scan for the JGS516PE  switch.

 

I understand that the switch is EOL and no longer supported but is there any information about the latest patch from them addresses the vulnerability mentioned?


6 Replies

Replies have been turned off for this discussion
  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Chipperchoi,

     

    Kindly check the Security Updates here.  If ever it does not include the vulnerability you have mentioned, you can report it by clicking the button "Click Here" under Report Vulnerabilities.

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

    • Chipperchoi's avatar
      Chipperchoi
      Aspirant

      That link doesn't address my question.

       

      If I were to report this, which is an old CVE by the way, will there be fixes for it if the product is EOL?


      It is a well known issue with opensource TCP/IP stack.

      • schumaku's avatar
        schumaku
        Guru - Experienced User

        Chipperchoi wrote:

        It is a well known issue with opensource TCP/IP stack.


        Not sure there are similar alternate robust and light TCP stacks available to replace these embedded microcontrollers TCP stacks not vulnerable to the Amnesia:33 set.

         

        Even if available, unclear if the industry will update these tiny devices ever.

         

        YeZ please.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More