The new update addresses several vulnerability issues

Aug 18, 2016 14:08 GMT  ·  By

NETGEAR has announced the availability of a new firmware package compatible with its GS510TP switch model, namely version 5.4.2.25, which removes a bug that caused the system to freeze when downloading the HTTPS/SSL certificate file to the switch.

If applied, this firmware will also fix flash logs disappearance after a system reboot, remove “Refresh” button from FLASH log page, and resolve the blocked EAP packet (with unicast destination address) in certain situations.

Moreover, the producer has managed to improve the port security with static MAC by implementing different settings, as well as to resolve the issue where certain optional TLV values of LLDP-MED were incorrect.

In addition to that, the present update addresses CVE-2011-3389, CVE-2009-3555, CVE-2013-2566, and CVE-2015-2808 security vulnerabilities. However, the CVE-2011-3389 issues will still be encountered in certain situations.

To be clear, for this latter problem, owners must disable TLSv1 protocol that will prevent legacy clients (that don’t support SSLv3 protocols) from establishing SSL connection with the switch. Also, enabling back this mode will be prone to CVE-2011-3389.

When it comes to installation, first back up all values changes from the default settings, save and unzip the downloadable archive, and use it to upgrade the device from the Firmware Update section.

That said, download NETGEAR GS510TP Switch Firmware 5.4.2.25, and carefully apply it to your unit to enjoy these new changes. Also, check back with us as often as possible to stay up to speed with the latest releases.