PT-2019-19766 · Safenet · Esafenet Cdg

Published

2019-03-08

·

Updated

2020-08-24

·

CVE-2019-9632

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESAFENET CDG versions V3 and V5
Description The issue concerns an arbitrary file download vulnerability. It can be exploited via the fileName parameter in the "download.jsp" endpoint, specifically when the InstallationPack parameter is mishandled in a "/CDGServer3/ClientAjax" request.
Recommendations For versions V3 and V5, consider restricting access to the "download.jsp" endpoint until a fix is available. As a temporary workaround, avoid using the fileName parameter in the "/CDGServer3/ClientAjax" request to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-9632

Affected Products

Esafenet Cdg