HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-7161

CVSS 7.3v3.1pub. 2023-12-29upd. 2024-11-21

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file index.php?para=index of the component Login. The manipulation of the argument check_VirtualSiteId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249183.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Netentsec Application Security Gateway

    HW
    Netentsec
    all versions
  • Netentsec Application Security Gateway Firmware

    OS
    Netentsec
    6.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-30242CRITICAL9.8PL ✓same product

SQL injection w Netentsec NS-ASG v6.3 — komponent add_ikev2.php

CVE-2024-28521HIGH7.8same product

SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to ...

CVE-2024-2647HIGH7.3same product

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gat...

CVE-2023-6903HIGH7.3same product

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-30243HIGH7.5same product

Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allow...