× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

Re: JQuery issue ProSafe GS728TPv2 Switch

VMHP
Follower

JQuery issue ProSafe GS728TPv2 Switch

Hi

 

Recently we ran a Nessus scan for the switch above after updating firmware.

Nessus flagged a JQuery issue:

Description: According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities. Note, the vulnerabilities referenced in this plugin have no security impact on PAN-OS, and/or the scenarios required for successful exploitation do not exist on devices running a PAN-OS release. Solution: Upgrade to JQuery version 3.5.0 or later.

Can anyone could tell me how to upgrade this or if it can be ignored please?

Model: GS728TPv2|24-Port Gigabit Ethernet PoE+ Smart Managed Pro Switch with 4 SFP Ports (190W)
Message 1 of 9
schumaku
Guru

Re: JQuery issue ProSafe GS728TPv2 Switch

@JohnC_V please.

Message 2 of 9
JohnC_V
NETGEAR Moderator

Re: JQuery issue ProSafe GS728TPv2 Switch

@VMHP,

 

I have sent you a private message.

 

Regards,

 

John

NETGEAR Community Team

Message 3 of 9
Millwaar
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch

Hi John, 

 

I'm also having the same issue, would you mind dropping me a line? 

 

Thanks. 

Message 4 of 9
Tonymnemonic
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch

I am getting a similar vulnerability with AlienVault.  jQuery is vulnerable to Cross-site Scripting (XSS) attacks. Is there a way to update jQuery?

Model: GS752TPSB|ProSafe 52 ports gigabit stackable smart switch with PoE
Message 5 of 9
JDGT
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch


@JohnC_V wrote:

@VMHP,

 

I have sent you a private message.

 

Regards,

 

John

NETGEAR Community Team


@JohnC_V I have also been inform of a the JQuery vulnerabilty version issue.  Could you please reach out to me as well?

 

S3300-52X-PoE+

Model: S3300-52X-PoE+ (GS752TXP)|ProSafe 48 ports stackable smart switches with PoE+
Message 6 of 9
lr-ssb
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch

I am having this same issue. Nessus detects jquery 1.6.2 installed on my Netgear switch

Model: M4100-24G-POE+ (GSM7224P)|ProSAFE Gigabit L2+ Managed Switch
Message 7 of 9
JDGT
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch

Hello,

 

Looking for an update to this issue.  Is there an ETA for a patch release to address the JQuery vulnerability?

Model: S3300-52X-PoE+ (GS752TXP)|ProSafe 48 ports stackable smart switches with PoE+
Message 8 of 9
chpc
Aspirant

Re: JQuery issue ProSafe GS728TPv2 Switch

We could also use an update, our vulnerability scan is showing:

 

jQuery End of Life (EOL) Detection (Linux) (OID: 1.3.6.1.4.1.25623.1.0.117149) Version used: 2021-06-11T09:02:34Z

 

Solution:

Update jQuery on the remote host to a still supported version.

Message 9 of 9
Top Contributors
Discussion stats
  • 8 replies
  • 2696 views
  • 0 kudos
  • 8 in conversation
Announcements