Lucene search

K
cve[email protected]CVE-2023-30806
HistoryOct 10, 2023 - 3:15 p.m.

CVE-2023-30806

2023-10-1015:15:10
CWE-78
web.nvd.nist.gov
36
sangfor
next-gen application firewall
ngaf8.0.17
cve-2023-30806
os command injection
vulnerability
remote exploitation

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.047 Low

EPSS

Percentile

92.7%

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie.

Affected configurations

NVD
Node
sangfornext-gen_application_firewallMatchngaf8.0.17

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Linux"
    ],
    "product": "Net-Gen Application Firewall",
    "vendor": "Sangfor",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.17"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.047 Low

EPSS

Percentile

92.7%

Related for CVE-2023-30806