Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22620

Опубликовано: 12 апр. 2023
Источник: nvd
CVSS3: 7.5
EPSS Высокий

Описание

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:securepoint:unified_threat_management:*:*:*:*:*:*:*:*
Версия от 12.2.3.1 (включая) до 12.2.5.1 (исключая)

EPSS

Процентиль: 99%
0.878
Высокий

7.5 High

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 7.5
github
почти 3 года назад

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

EPSS

Процентиль: 99%
0.878
Высокий

7.5 High

CVSS3

Дефекты

CWE-863
CWE-863