PT-2024-23636 · Netentsec · Netentsec Ns-Asg
Hundanchen69
·
Published
2024-04-01
·
Updated
2025-04-04
·
CVE-2024-30859
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
netentsec NS-ASG version 6.3
Description
The issue concerns a SQL injection vulnerability. It can be exploited via the "/admin/config ISCGroupSSLCert.php" API endpoint. This could potentially allow for remote attacks.
Recommendations
For netentsec NS-ASG version 6.3, patch immediately and validate input data to prevent exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netentsec Ns-Asg