MEDIUM🇬🇧 English

CVE-2024-2648

CVSS 4.3v3.1pub. 2024-03-19upd. 2025-01-30

A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath expressions. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257286 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Netentsec Application Security Gateway

    APP
    Netentsec
    6.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-30242CRITICAL9.8PL ✓ten sam produkt

SQL injection w Netentsec NS-ASG v6.3 — komponent add_ikev2.php

CVE-2024-2647HIGH7.3ten sam produkt

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gat...

CVE-2023-7161HIGH7.3ten sam produkt

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-6903HIGH7.3ten sam produkt

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-30243HIGH7.5ten sam produkt

Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allow...