PT-2024-21397 · Netentsec · Netentsec Ns-Asg Application Security Gateway
18070802606
·
Published
2024-03-19
·
Updated
2025-01-30
·
CVE-2024-2648
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Netentsec NS-ASG Application Security Gateway version 6.3
Description
A problematic issue was found in the affected software, where an unknown function of the file /nac/naccheck.php is impacted. The manipulation of the
username argument leads to improper neutralization of data within xpath expressions. This allows for a remote attack. The issue has been publicly disclosed and may be exploited.Recommendations
Netentsec NS-ASG Application Security Gateway version 6.3: Update the software to a version where this issue is resolved, or apply a patch if provided by the vendor to fix the improper neutralization of data within xpath expressions. As a temporary workaround, consider restricting access to the /nac/naccheck.php file or disabling the unknown function impacted by this issue until a patch is available. Avoid using the
username argument in the affected function until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netentsec Ns-Asg Application Security Gateway