MEDIUM🇵🇱 Wersja polska

CVE-2024-2648

CVSS 4.3v3.1pub. 2024-03-19upd. 2025-01-30

A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath expressions. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257286 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Netentsec Application Security Gateway

    APP
    Netentsec
    6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-30242CRITICAL9.8PL ✓same product

SQL injection w Netentsec NS-ASG v6.3 — komponent add_ikev2.php

CVE-2024-2647HIGH7.3same product

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gat...

CVE-2023-7161HIGH7.3same product

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-6903HIGH7.3same product

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-30243HIGH7.5same product

Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allow...